OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Ipchains!
From: Dimuthu Parussalla (dparussallaBAYSIDEGRP.COM.AU)
Date: Sun May 07 2000 - 20:07:42 CDT


Ipchains buffer overflow with debian 2.2.10 Kernel.
--------------------------------------------------

there is a buffer overflow hang in linux debian distributin kernel 2.2.10
with ipchains 1.3.8, 27-Oct-1998.

here is the explanation.

We tested with a linux running with debian above version of kernel and
ipchains. first we setup the linux box to handle IP Masquerading as follows.

ipchains -A forward -j MASQ -s 192.168.0.0/16

Then from a local workstation within the 192.168.0.0 network. We ssh to the
linux box. and did the following

$ping -f <ip.address>

And we opend a another ssh session to the linux box and did the following

$ping -l 6512121 <ip.address>

After a few minutes. Ipchains hangs and the linux server hangs..

Ipchains-patch.gz will fix the problem.

----------------------
THE UNDERTAKER -> EFNET -> REAL CRACKING

!!!REST IN PACE!!!!