Links

Lists

Latest Updates

Ruby On Rails List
Python list
Advanced Java
The JavaScript List
Apache Users
Full Disclosure
Linux Security

Search the archives!


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[linux-security] Re: portmap vulnerability?


  • From: Matt <panzer@xxxxxxx>
  • Subject: [linux-security] Re: portmap vulnerability?
  • Date: 12 Dec 1998 06:32:41 GMT

In mail.linux.security Tony Nugent <Tony.Nugent@xxxxxxxxxx> wrote:
: To make this post worthwhile, where is a snippit out of my own
: /etc/hosts.deny file...

: " | /bin/mail -s "$(uname -n) wrappers\: %d refused for %c" \
: root@localhost ) &

It was very tempting send a pile of spoofed packets into your network to
generate a huge load of email, filling up your mail spool and generating a
nice load on your system. :)

As tempting as this type of logging usually is, perhaps you want to dump
it to a file, instead of having every connection attempted emailed to you,
generating a handful of proccesses while it does so.


[mod: Some remarked that things like "%u" are "client controlled" and
could be used to exploit Tony's system. The manual however claims:

      Characters in % expansions that may confuse the shell  
      are replaced by underscores.

so that should be OK. -- REW]

-- 
-Matt Drown     -- Privacy, Anonyminity, & Security -- DataHaven Project
 panzer@xxxxxxx -- Shell and Web accounts           -- http://www.dhp.com/