Re: xinetd bug or new DoS attack?

Steve G <[email protected]> Fri, 2 Jan 2004 10:34:56 -0800 (PST)
Newsgroups gmane.network.xinetd
Message-ID <[email protected]>
>We've identified a potential problem in the current version 
>of xinetd (2.3.12) that may be a defect of the code itself, 
>or a possible new form of DOS attack.

Yes indeed. There are several more places where this could pop up
in the code and we don't handle it well. At best, they can do a
DOS attack.

The correct action is to suspend the offending services when this
occurs. This will close & remove the listening descriptor from
the select loop and you won't see the problem any more. Ending or
restarting xinetd is not good either.

I will code something up and put into cvs this afternoon. Thanks
for the bug report.

-Steve Grubb

__________________________________
Do you Yahoo!?
Find out what made the Top Yahoo! Searches of 2003
http://search.yahoo.com/top2003