Re: Overflow in tcplog.c (VD#3)

From: CyberPsychotic (fygraveat_private)
Date: Thu Nov 04 1999 - 07:49:31 PST

  • Next message: dark spyrit: "Interscan VirusWall NT 3.23/3.3 buffer overflow."

    ~ :I was just visiting  http://www.echelon.wiretapped.net and downloaded a
    ~ :small file called "tcplog.c" with no author or version stated.  It is for
    ~ :logging connections to your box (linux only).
    ~ :
    ~ :There are some minor coding gripes I could make, but line 107
    ~ :takes a risk with the size of a hostname
    ~ :
    ~ :    98  char *hostlookup(unsigned long int in)
    ~ :    99  {
    
    Yep. I have notified phroid about the problem about a year ago or so,
    while was adding some additional features to his code, and he told me he
    took care of the problem. I also have added several other features to his
    code (and fixed the bug of course). If intersted, you could check the code
    out at http://www.kalug.lug.net/tcplogd/.
    
    hope it helps.
    
    Fyodor
    
    --
    * Some day this will be a full-fledged user tracking system..
    - <linux/sched.h>
    			http://www.kalug.lug.net/fygrave/
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 15:09:53 PDT