OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: redhat-6.2 snmpd
From: Chris Evans (chrisferret.lmh.ox.ac.uk)
Date: Fri May 05 2000 - 09:21:48 CDT


On Fri, 5 May 2000, Adam Goryachev wrote:

> somehow getting into some trouble somewhere. BTW, snmpd runs as user root.

I've had an allegation that snmpd can be used for worse than DoS... I have
not had time to visit the issue however. I have no idea whether the
allegation has any factual basis...

Anyone want to have a look at the snmpd code? A good starting point would
be the handling of data sent to the listening network socket.

Cheers
Chris