From owner-freebsd-security@FreeBSD.ORG Tue May 27 08:05:44 2014 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTPS id EEC6EBC4 for ; Tue, 27 May 2014 08:05:44 +0000 (UTC) Received: from smtp.des.no (smtp.des.no [194.63.250.102]) by mx1.freebsd.org (Postfix) with ESMTP id B27692AD3 for ; Tue, 27 May 2014 08:05:44 +0000 (UTC) Received: from nine.des.no (smtp.des.no [194.63.250.102]) by smtp-int.des.no (Postfix) with ESMTP id AE47DA4E5; Tue, 27 May 2014 08:05:42 +0000 (UTC) Received: by nine.des.no (Postfix, from userid 1001) id E3BD331226; Tue, 27 May 2014 10:05:23 +0200 (CEST) From: =?utf-8?Q?Dag-Erling_Sm=C3=B8rgrav?= To: "Ronald F. Guilmette" Subject: Re: NEVERMIND! References: <7159.1401134516@server1.tristatelogic.com> Date: Tue, 27 May 2014 10:05:23 +0200 In-Reply-To: <7159.1401134516@server1.tristatelogic.com> (Ronald F. Guilmette's message of "Mon, 26 May 2014 13:01:56 -0700") Message-ID: <867g57bq9o.fsf@nine.des.no> User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/24.3 (berkeley-unix) MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Cc: freebsd-security@freebsd.org X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 27 May 2014 08:05:45 -0000 "Ronald F. Guilmette" writes: > So should I file a PR on this, or what? *shrug* I think this falls under the same heading as a fork bomb - one of thousands of ways local users can screw you over if they want to. > For example, I can easily envision remotely filling up your /var simply > by sending you, in rapid succession, a sufficient quantity of malformed > http requests, or perhaps even just an endless set of minimalist HELO/QUIT > sequences to your mail server. or an ssh brute force scan, etc. In my opinion, this belongs in a system administration textbook, not in a bug tracker. DES --=20 Dag-Erling Sm=C3=B8rgrav - des@des.no