Great Circle Associates Firewalls
(January 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: List of firewall log attack signatues?
From: Christopher Klaus <cklaus @ shadow . net>
Date: Wed, 18 Jan 1995 09:49:33 -0500 (EST)
To: mjr @ tis . com (Marcus J Ranum)
Cc: an119810 @ anon . penet . fi, firewalls @ GreatCircle . COM
In-reply-to: <9501180311 . AA03710 @ tis . com> from "Marcus J Ranum" at Jan 17, 95 10:17:56 pm

> 
> > Moral: disable the program mailer!
> 
> 	Yep. Actually, I leave it in, and replace it with a script
> that sends the admin a nice note including the mail message and
> all its command lines. You can catch the most amazing fish that
> way. One goof was mailing around a script to build a minimal sockd,
> intended to compile and execute on any firewall it could trigger
> the sendmail bug upon. Pretty nasty stuff.

Yea, Scott Chasin posted that sendmail sockd script to Firewalls a while
ago. Fortunately, it only worked on SunOs4.x.  With some minor
modifications, it could work on AIX, Ultrix, etc.  I believe CERT said
they reported a substancial breakin increase like the day after Scott
posted it also.  ISS checks for that bug, and you would be suprised
within a given site, how many machines pop up vulnerable, ready for any 
intruder to pluck. 

 Christopher

-- 
Christopher William Klaus	Voice: (404)518-0099. Fax: (404)518-0030
Internet Security Systems, Inc.		Computer Security Consulting
2209 Summit Place Drive, Atlanta, GA. 30350-2450.


References:
Indexed By Date Previous: Re[2]: List of firewall log attack signatues?
From: jmeritt @ smtpinet . aspensys . com (Meritt, Jim)
Next: Re: Cisco Logging
From: Howard Berkowitz <hcb @ clark . net>
Indexed By Thread Previous: Re: List of firewall log attack signatues?
From: Marcus J Ranum <mjr @ tis . com>
Next: Re[2]: List of firewall log attack signatues?
From: jmeritt @ smtpinet . aspensys . com (Meritt, Jim)

Google
 
Search Internet Search www.greatcircle.com