mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Matti Aarnio <matti.aarnio@zmailer.org>
To: "Randal, Phil" <prandal@herefordshire.gov.uk>
Cc: linux-kernel@vger.kernel.org
Subject: Re: TRG vger.timpanogas.org hacked
Date: Tue, 5 Jun 2001 14:07:15 +0300	[thread overview]
Message-ID: <20010605140715.M5947@mea-ext.zmailer.org> (raw)
In-Reply-To: <AFE36742FF57D411862500508BDE8DD00199501D@mail.herefordshire.gov.uk>
In-Reply-To: <AFE36742FF57D411862500508BDE8DD00199501D@mail.herefordshire.gov.uk>; from prandal@herefordshire.gov.uk on Tue, Jun 05, 2001 at 11:33:57AM +0100

On Tue, Jun 05, 2001 at 11:33:57AM +0100, Randal, Phil wrote:
> Bind 8.2.4 was released on May 17th, with the standard
> comment "BIND 8.2.4 is the latest version of ISC BIND 8.
> We strongly recommend that you upgrade to BIND 9.1 or, if
> that is not immediately possible, to BIND 8.2.4 due to
> certain security vulnerabilities in previous versions."
> 
> However, there are no release notes on ISC's web site,
> and their vulnerabilities page lists no known security
> flaws in Bind 8.2.3.

	That's quaint...

	The 8.2.4 got some immunity on running out of low fd numbers 
	suitable for stdio at e.g. Solaris.
	(Is there anything else, I haven't checked.)

	Essentially it makes system a bit more resistant against
	(possibly unintentional) denial of service attacks when
	there are heaps and troves of TCP based resolving connections.

	All you need is to have some zone with so massive replies for
	some questions that it does not fit into UDP query/reply packet.
	E.g. have a few dozen different PTR records for some IP address,
	and you will soon see what I mean.

	Run that bind at some saturated load system so that the bind is
	slow as molass, and have lots of people asking for reversers...
	I can pretty much guarantee that you will see what bind 8.2.3
	barfs within a day or so.  Your only solution is to restart the
	8.2.3.  (It fails to act as resolver after the barf until reboot,
	it may also loose one or more of your DNS zones.)

	I haven't checked if 9.1.* series is also immunized for this.
	(That is, if it uses stdio for any file accesses anymore.)

> But the paranoid part of me does wonder :-)

	What else there might be...

> (And I haven't the time to do the diffs to see what's
> changed.)
> 
> Cheers,
> 
> Phil
> 
> ---------------------------------------------
> Phil Randal
> Network Engineer
> Herefordshire Council
> Hereford, UK 
> 
> > -----Original Message-----
> > From: Daniel Roesen [mailto:dr@bofh.de]
> > Sent: 05 June 2001 11:14
> > To: linux-kernel@vger.kernel.org
> > Subject: Re: TRG vger.timpanogas.org hacked
> > 
> > 
> > On Tue, Jun 05, 2001 at 08:05:34AM +0100, Alan Cox wrote:
> > > > is curious as to how these folks did this.  They 
> > exploited BIND 8.2.3
> > > > to get in and logs indicated that someone was using a 
> > "back door" in 
> > > 
> > > Bind runs as root.
> > 
> > Not if set up properly. And there is no known hole in BIND 8.2.3-REL
> > so I'm wondering how Jeff found out that the intruder got in via BIND.
> > -
> > To unsubscribe from this list: send the line "unsubscribe 
> > linux-kernel" in
> > the body of a message to majordomo@vger.kernel.org
> > More majordomo info at  http://vger.kernel.org/majordomo-info.html
> > Please read the FAQ at  http://www.tux.org/lkml/
> > 
> -
> To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
> the body of a message to majordomo@vger.kernel.org
> More majordomo info at  http://vger.kernel.org/majordomo-info.html
> Please read the FAQ at  http://www.tux.org/lkml/

  reply	other threads:[~2001-06-05 11:07 UTC|newest]

Thread overview: 11+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2001-06-05 10:33 Randal, Phil
2001-06-05 11:07 ` Matti Aarnio [this message]
2001-06-05 17:19 ` Brian Wellington
  -- strict thread matches above, loose matches on Subject: below --
2001-06-05  1:36 Jeff V. Merkey
2001-06-05  7:05 ` Alan Cox
2001-06-05 10:14   ` Daniel Roesen
2001-06-05 14:10   ` Michael H. Warfield
2001-06-05 18:30   ` Jeff V. Merkey
2001-06-05 18:42     ` Michael H. Warfield
2001-06-05 13:07 ` Henning P. Schmiedehausen
2001-06-05 13:41   ` Daniel Roesen

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20010605140715.M5947@mea-ext.zmailer.org \
    --to=matti.aarnio@zmailer.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=prandal@herefordshire.gov.uk \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®