Re: Novell NetWare webservers DoS

From: Przemyslaw Frasunek (venglinat_private)
Date: Thu Jun 17 1999 - 11:06:35 PDT

  • Next message: Winfried Truemper: "Security extensions to Posix (what would have been Posix.1e/2c)"

    > I have tested your exploit on Yawn HTTPD in various environment
    > (NetWare 3.11, 3.12, 4.10, 4.11) and I'm quite sure the program
    > should not crash the NetWare with my web server on the top.
    > Can anybody correct me or provide additional information?
    
    As you said, the problem is probably related to the amount of MaxThreads
    parameter in httpd.cfg, which is default set to 16 (this is a safe value).
    
    Setting it to more than 16 can be dangerous, because of exhausting the server
    memory, when many parallel connections are opened.
    
    --
    * Fido: 2:480/124 ** WWW: lagoon.freebsd.org.pl/~venglin ** GSM:48-601-383657 *
    * Inet: venglinat_private ** PGP:D48684904685DF43EA93AFA13BE170BF *
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 14:50:00 PDT