看板FB_security
标 题Re: Full-Disclosure posting "FreeBSD 9.1 ftpd Remote Denial of
发信站NCTU CS FreeBSD Server (Tue Feb 5 07:28:53 2013)
转信站ptt!csnews.cs.nctu!news.cs.nctu!.cs.nctucs.nctu!!freebsdfreebsd.org!ow
On Mon, Feb 4, 2013 at 6:27 PM, Fabian Wenk <
[email protected]> wrote:
> A few days ago there was the posting "FreeBSD 9.1 ftpd Remote Denial of
> Service" [1] on the Full-Disclosure mailing list. Is this a known issue to
> the FreeBSD community?
>
> [1]
> http://lists.grok.org.uk/pipermail/full-disclosure/2013-February/089583.html
>
> There are also many ftp.*.freebsd.org mirrors listed in the above mention
> posting, so I also put freebsd-hubs@ into the recipient list. This will
> probably help, that ftp mirror operators are alerted and can take any action
> if needed.
I can confirm this is an issue on stable/9 r245742. Though I hardly
can call it DoS as normally ftp account is running with well-defined
ulimits and proper ftpd usage pattern does not generate much CPU
usage, so you can keep limits pretty much low, thus not being affected
by so-called "DoS".
Nevertheless any ideas on how to fix our glob(3)?
Regards,
Alexandr.
_______________________________________________
[email protected] mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "
[email protected]"