[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Is there a FAM(file alteration monitor) exploit in the wild?



Dec  6 16:08:07 plaguesplace fam[3044]: fd 5 message length 67181060
bytes exceeds max of 4136.
Dec  6 16:08:07 plaguesplace fam[3044]: fd 6 message length 1129270862
bytes exceeds max of 4136.
Dec  6 16:08:07 plaguesplace fam[3044]: fd 5 message length 83951621
bytes exceeds max of 4136.
Dec  6 16:08:10 plaguesplace fam[3044]: fd 5 message length 1347375956
bytes exceeds max of 4136.
Dec  6 16:08:12 plaguesplace in.telnetd[16701]: refused connect from
pberetta@blondes.have.more.fun.on.thundercity.net
Dec  6 16:08:12 plaguesplace in.telnetd[16700]: refused connect from
pberetta@blondes.have.more.fun.on.thundercity.net

Dec  7 16:21:11 plaguesplace fam[3044]: fd 5 message length 1129270862
bytes exceeds max of 4136.
Dec  7 16:21:11 plaguesplace fam[3044]: fd 5 message length 1347375956
bytes exceeds max of 4136.
Dec  7 16:21:11 plaguesplace fam[3044]: fd 5 message length 67181060
bytes exceeds max of 4136.
Dec  7 16:21:14 plaguesplace fam[3044]: fd 5 message length 83951621
bytes exceeds max of 4136.
Dec  7 16:21:16 plaguesplace in.telnetd[18227]: refused connect from
pberetta@blondes.have.more.fun.on.thundercity.net
Dec  7 16:21:16 plaguesplace in.telnetd[18228]: refused connect from
pberetta@blondes.have.more.fun.on.thundercity.net


According to tcpd(8) I cannot protect this program with tcp/wrappers:
"The program does not work with RPC services over TCP. These services are
registered as rpc/tcp in the inetd configuration file."

The local-only security options do not work when called from inetd.  How
are you supposed to protect this program?  Firewall?

I turned it off for now:(

joe
-- 

Attachment: pgpQxInpyPlHb.pgp
Description: PGP signature


Reply to: