[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Is there a FAM(file alteration monitor) exploit in the wild?



why do you run that kind of service on a publicly reachable  address ? 
firewall yourself asap.


On Sun, Dec 07, 2003 at 07:25:54PM -0500, Me wrote:
> Dec  6 16:08:07 plaguesplace fam[3044]: fd 5 message length 67181060
> bytes exceeds max of 4136.
> Dec  6 16:08:07 plaguesplace fam[3044]: fd 6 message length 1129270862
> bytes exceeds max of 4136.
> Dec  6 16:08:07 plaguesplace fam[3044]: fd 5 message length 83951621
> bytes exceeds max of 4136.
> Dec  6 16:08:10 plaguesplace fam[3044]: fd 5 message length 1347375956
> bytes exceeds max of 4136.
> Dec  6 16:08:12 plaguesplace in.telnetd[16701]: refused connect from
> pberetta@blondes.have.more.fun.on.thundercity.net
> Dec  6 16:08:12 plaguesplace in.telnetd[16700]: refused connect from
> pberetta@blondes.have.more.fun.on.thundercity.net
> 
> Dec  7 16:21:11 plaguesplace fam[3044]: fd 5 message length 1129270862
> bytes exceeds max of 4136.
> Dec  7 16:21:11 plaguesplace fam[3044]: fd 5 message length 1347375956
> bytes exceeds max of 4136.
> Dec  7 16:21:11 plaguesplace fam[3044]: fd 5 message length 67181060
> bytes exceeds max of 4136.
> Dec  7 16:21:14 plaguesplace fam[3044]: fd 5 message length 83951621
> bytes exceeds max of 4136.
> Dec  7 16:21:16 plaguesplace in.telnetd[18227]: refused connect from
> pberetta@blondes.have.more.fun.on.thundercity.net
> Dec  7 16:21:16 plaguesplace in.telnetd[18228]: refused connect from
> pberetta@blondes.have.more.fun.on.thundercity.net
> 
> 
> According to tcpd(8) I cannot protect this program with tcp/wrappers:
> "The program does not work with RPC services over TCP. These services are
> registered as rpc/tcp in the inetd configuration file."
> 
> The local-only security options do not work when called from inetd.  How
> are you supposed to protect this program?  Firewall?
> 
> I turned it off for now:(
> 
> joe
> -- 



-- 

-> Jean-Francois Dive
--> jef@linuxbe.org

  I think that God in creating Man somewhat overestimated his ability.
  -- Oscar Wilde

Attachment: pgpHW5ui87kn8.pgp
Description: PGP signature


Reply to: