Re: inetd vulnerability

From: Chris Conner (chrisat_private)
Date: Tue Sep 15 1998 - 16:18:54 PDT

  • Next message: Alan Brown: "Re: rpc.mountd vulnerabilities"

    As far as I can see, all this script does is make a large number of
    connections to a single port. The inetd man pages allow you to put an
    argument after 'wait' or 'nowait' in inetd.conf for any service. (wait.256)
    this allows 256 connections in a minute, compared to the default 40. This
    script will still kill the port when it is set to 256, so maybe someone can
    hack something up to make inetd allow more than 256 connections in under a
    minute?
    
    Chris
    
    At 05:04 PM 9/29/98 -0400, you wrote:
    >I was talking to someone on irc last night after I made my post about the
    >mountd exploit and they said they had a exploit that would kill inetd.
    >I did not get the stuff but I had him try it on 3 of my linux systems and
    >it did work..
    >morex .-
    >http://morex.net
    >http://www.worldnetworks.net
    >
    >
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 14:18:19 PDT