Ascend has fixed this UDP problem since March 25.
See ftp://ftp.ascend/pub/Software-Releases/Pipeline/Release-6.0.x/6.0.2/doc
At 14:21 08/04/98 -0400, Ken Jones wrote:
>
>On Wed, 8 Apr 1998, Michael Simonyi wrote:
>> Does anyone know of or heard of security issues with an Ascend Pipeline 25.
>>
>> Mike
>>
>
>Yes. The pipelines come with simple packet filtering features. They
>also sell a firewall package for about $500. I don't know if this
>is any good.
>
>There is a known exploit for ascend pipelines. Information on it
>is available at www.rootshell.com. Basicly you send the pipeline
>a certain UDP packet at port 9 and it locks up. The pipeline site
>has a method for adding a packet filter to block it out, but they
>have no fix yet. We tested the exploit against a pipeline 75 and it
>indeed locked up and had to be power cycled.
>
>Ken Jones
>kbo @
inter7 .
com
>www.inter7.com
>
>
>
|
|