From owner-freebsd-audit Fri Dec 8 16: 0: 7 2000 From owner-freebsd-audit@FreeBSD.ORG Fri Dec 8 16:00:06 2000 Return-Path: Delivered-To: freebsd-audit@freebsd.org Received: from puck.firepipe.net (mcut-b-167.resnet.purdue.edu [128.211.209.167]) by hub.freebsd.org (Postfix) with ESMTP id E987A37B400 for ; Fri, 8 Dec 2000 16:00:05 -0800 (PST) Received: by puck.firepipe.net (Postfix, from userid 1000) id 856E118CF; Fri, 8 Dec 2000 19:00:04 -0500 (EST) Date: Fri, 8 Dec 2000 19:00:04 -0500 From: Will Andrews To: Mike Silbersack Cc: freebsd-audit@FreeBSD.ORG Subject: Re: bitchx/ircd DNS overflow demonstration (fwd) Message-ID: <20001208190004.S572@puck.firepipe.net> Reply-To: Will Andrews References: Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline User-Agent: Mutt/1.2.5i In-Reply-To: ; from silby@silby.com on Fri, Dec 08, 2000 at 12:34:35AM -0600 X-Operating-System: FreeBSD 4.2-STABLE i386 Sender: will@puck.firepipe.net Sender: owner-freebsd-audit@FreeBSD.ORG Precedence: bulk X-Loop: FreeBSD.ORG On Fri, Dec 08, 2000 at 12:34:35AM -0600, Mike Silbersack wrote: > Since people appear to be on an auditing rampage, I thought I'd forward > this over to the list. It describes some DNS parsing bugs in a few ircds > and BitchX that seem to have serious consequences. It may be worth a look > into if programs in the base system have similar problems. Err, this is out of the list's charter IMO. We're only here to audit code in FreeBSD itself. Anyone want to clarify the charter? Actually, I don't see any charter anywhere.. -- wca To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-audit" in the body of the message