Re: easy DoS in most RPC apps

From: Scott Stone (sstoneat_private)
Date: Sun May 17 1998 - 09:29:26 PDT

  • Next message: Bill Paul: "Re: easy DoS in most RPC apps"

    On Sun, 17 May 1998, David LeBlanc wrote:
    
    > At 02:35 AM 5/15/98 +0200, Peter van Dijk wrote:
    > >Finally, I'm quite sure of this: the bug is in Sun's RPC code.
    > >Investigations show Linux, FreeBSD, SunOS, System V and NeXTstep machines
    > >are affected, which means we've got a _big_ problem here.
    >
    > If that's the case, then any ports of these utilities running on Windows NT
    > would also exhibit the same problem - we're all running off of pretty much
    > the same Sun ONC RPC code.
    >
    
    The FreeBSD people have already made a patch for this, check their home
    site.  I'm going to attempt to port the patch to Linux, as the base code
    should be about the same.. the fix is to a couple of rpc-related files in
    the C libraries.
    
    --------------------------------------------------
    Scott M. Stone <sstoneat_private, sstoneat_private>
                   <sstoneat_private>
    Linux Developer/Systems Administrator for Pacific HiTech, Inc.
    http://www.pht.com              http://armadillo.pht.co.jp
    http://www.pht.co.jp            http://www.turbolinux.com
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 13:53:50 PDT