Vulnerability Development mailing list archives
BEWARE : Possible compromission under BIND 8.2.2-P5 with Iquery probe
From: ml <ml () BLAS NET>
Date: Fri, 9 Mar 2001 20:21:20 +0100
Hi,
I have a bind. This BIND is a 8.2.2-P5 version which announces itself as being a V4 BIND.
This BIND runs under a non privileged account.
Regularly, attackers send a Iquery (as report by Snort signature) probe on it that crashes it.
It the first curiosity : V8 BIND is not sensitive to Iquery attack as far as I know !
Well, an automatic procedure detects this crash and relaunches it just after.
By now, sorry, but I was not able to dump the full trace (snort refuses t
Today, the scenario was different :
BIND crashes as always just after the Iquery but
somebody relaunches it just after the crash.
AND this WITHOUT arguments -u and -g.
That is to say, BIND was relaunched under the non-privileged account it uses to run under :
according to the log, it was unable to bind to port 53 !
Conclusion : I think it's possible to get a shell under BIND 8.2.2-P5 and with a Iquery probe.
Do someone be aware of such a vulnerability ?
db
Current thread:
- BEWARE : Possible compromission under BIND 8.2.2-P5 with Iquery probe ml (Mar 09)
- Re: BEWARE : Possible compromission under BIND 8.2.2-P5 with Iquery probe Gossi The Dog (Mar 10)
- Re: BEWARE : Possible compromission under BIND 8.2.2-P5 with Iquery probe David R. Conrad (Mar 12)
- Re: BEWARE : Possible compromission under BIND 8.2.2-P5 with Iquery probe Daniel Roesen (Mar 13)
- Re: BEWARE : Possible compromission under BIND 8.2.2-P5 with Iquery probe David R. Conrad (Mar 13)
- Re: BEWARE : Possible compromission under BIND 8.2.2-P5 with Iquery probe Daniel Roesen (Mar 14)
- Cross site scripting with SAP Aurélien Cabezon [iSecureLabs] (Mar 14)
- Re: BEWARE : Possible compromission under BIND 8.2.2-P5 with Iquery probe Daniel Roesen (Mar 13)
