OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Bugtraq archives for 4th quarter (Oct-Dec) 1996: Re: BoS: Urgent !! Serious Linux Security Bug....

Re: BoS: Urgent !! Serious Linux Security Bug....

Eli Burke (eburkecslab.vt.edu)
Mon, 21 Oct 1996 00:14:13 -0400

> Subject: Re: BoS: Urgent !! Serious Linux Security Bug....
> > cy>> >        Today we saw an email from Linus Torvalds advising of a problem
> > cy>> >with Linux and ping.  Basically you can reboot a linux box remotely if
> > cy>> >some scenario's are right.  From what we can tell and this has all been
> > cy>> >verified is: If anyone in the world with a Windows 95 machine can ping
> > cy>> >your Linux box they can potentially reboot that machine..
> >
> > My Friend tested in this machines:
> > >       1) Reboot: OSF/1 3.2C, Solaris2.4 x86
>
>         I tested this under OSF/1 3.2 and had no problems. Same for DUnix 4.0,
> Ultrix 4.4, Windows NT 4.0 (server and workstation), and FreeBSD 2.1.5.
[snip]

        Wiping off the egg, I take back what I said. This successfully crashes
OSF/1 3.2 and DUnix 4.0 _when done from WinNT or Win95_. Thanks Bill. :)

--
Eli Burke
eburkevt.edu
http://csugrad.cs.vt.edu/~eburke/