OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Charles Sprickman (sporkINCH.COM)
Date: Thu Apr 05 2001 - 19:03:38 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    On Wed, 4 Apr 2001, Przemyslaw Frasunek wrote:

    > /* ntpd remote root exploit / babcia padlina ltd. <venglinfreebsd.lublin.pl> */

    Just a quick note to save others a bit of legwork... If you are running
    ntpd on a machine simply as a client, the following line in /etc/ntp.conf
    should keep people away:

    restrict default ignore

    Before adding this (I actually had the wrong syntax), the exploit crashed
    ntpd. Afterwords, not a blip, and ntpdate shows that ntpd is not
    answering anything...

    Charles