[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: rlinetd security



On Mon, Jun 18, 2001 at 01:48:50PM -0400, Noah Meyerhans wrote:
> 
> Why not?  You've not given any reason at all.  Do you know of any
> malicious behavior that is made possible by leaving the services turned
> on?  The potential exists to use the chargen feature as a part of a DoS
> attack, but I've not heard of it ever being used as it's not
> particularly effective unless you have many many machines available, and
> even then there are much more effective weapons.  And what about the
> rest of the ports?  How are they dangerous?  I've never heard of an
> exploit involving any of them.

play a spoofing trick to attach the victims chargen port to its echo
port.  

i don't know if that is still possible, in the olden days it was, had
quite ammusing result too.  

-- 
Ethan Benson
http://www.alaska.net/~erbenson/

Attachment: pgphUW1G1K56q.pgp
Description: PGP signature


Reply to: