Re: xinetd bug or new DoS attack?
Matthias Andree <[email protected]> Wed, 07 Jan 2004 00:15:56 +0100
| Newsgroups | gmane.network.xinetd |
|---|---|
| Message-ID | <[email protected]> |
Steve G <[email protected]> writes: >>Typo :) Do you agree? > > Hmmm. The man 2 accept page says: > > EMFILE The per-process limit of open file descriptors has been > reached. > > ENFILE The system maximum for file descriptors has been reached. > > I guess I overlooked one. It should be an 'OR' condition...I just > fixed it in cvs. You can find the patch here: > > http://www.xinetd.org/pipermail/cvs-xinetd/2004-January/000221.html > > Thanks for the follow up. I, for one, would like hear feedback > next time you are attacked. It's good to know the problem was > handled. Wait a second. The service is disabled for 15 seconds when the connection rate is too high? That's the same non-working scheme found in inetd, disable any service that connects more than N times per minute for 10 minutes. It doesn't handle high or excessive load. Disabling the service for some time will bring people back in the time when the service is up, so it disables itself again... no good. If so, what advantage is xinetd over tcpsvd or tcpserver, apart from IPv6? -- Matthias Andree Encrypt your mail: my GnuPG key ID is 0x052E7D95