Re: hitting amanda client port with openvas causes 100% load on host machine

Jean-Louis Martineau <[email protected]> Tue, 16 Jan 2018 08:02:31 -0500
Newsgroups gmane.comp.archivers.amanda.devel
Message-ID <[email protected]>
Stefan,

To increase security, you should add the following line in the 
/etc/xinetd.d/amanda file:
     only_from               = IP-OF-AMANDA-SERVER

Can you send me one of the amandad.<TIMESTAMP>.debug file so I can look 
at what went wrong.

Jean-Louis

On 16/01/18 07:13 AM, Stefan Bauer wrote:
> hitting amanda client port with openvas causes 100% load on host machine
>
> Hi,
>
> while scanning our network with openvas 
> (http://www.openvas.org/index.de.html 
> <http://www.openvas.org/index.de.html>) 
> we noticed after hitting our server on the amanda port (10080) that 
> this causes a 100% cpu load on all cores.
>
> After this, 5 amanda procsses are up and running.
>
>
> We used the virtual machine image from openvas.org 
> <http://openvas.org> 
> without any special tunning. Just enter the server ip and hit quick-start.
>
>
> Only a kill of the amanda daemon solves the problem. Looks clearly 
> like a bug/security issue as it renders the server almost unusable.
>
>
> ii  amanda-client 1:3.3.6-4.1  amd64        Advanced Maryland 
> Automatic Network Disk Archiver (Client)
> ii  amanda-common  1:3.3.6-4.1  amd64        Advanced Maryland 
> Automatic Network Disk Archiver (Libs)
> root@host01:/home/user# more /etc/debian_version
> stretch/sid
>
>
> Amanda is started via xinetd
>
>
> root@host01:/home/user# more /etc/xinetd.d/amanda
>
> service amanda
> {
>         disable         = no
>         flags           = IPv4
>         socket_type     = stream
>         protocol        = tcp
>         wait            = no
>         user            = backup
>         group           = disk
>         groups          = yes
>         server          = /usr/lib/amanda/amandad
>         server_args     = -auth=bsdtcp amdump amindexd amidxtaped
> }
>
>
> Any help is greatly appreciated.
>
This message is the property of CARBONITE, INC. and may contain confidential or privileged information.
If this message has been delivered to you by mistake, then do not copy or deliver this message to anyone.  Instead, destroy it and notify me by reply e-mail