From owner-freebsd-hackers Mon Oct 21 07:07:35 1996 Return-Path: owner-hackers Received: (from root@localhost) by freefall.freebsd.org (8.7.5/8.7.3) id HAA14146 for hackers-outgoing; Mon, 21 Oct 1996 07:07:35 -0700 (PDT) Received: from rah.star-gate.com (rah.star-gate.com [204.188.121.18]) by freefall.freebsd.org (8.7.5/8.7.3) with ESMTP id HAA14137 for ; Mon, 21 Oct 1996 07:07:32 -0700 (PDT) Received: from rah.star-gate.com (localhost.star-gate.com [127.0.0.1]) by rah.star-gate.com (8.7.6/8.7.3) with ESMTP id HAA01221; Mon, 21 Oct 1996 07:07:17 -0700 (PDT) Message-Id: <199610211407.HAA01221@rah.star-gate.com> X-Mailer: exmh version 1.6.9 8/22/96 To: Jeremy Sigmon cc: hackers@freebsd.org Subject: Re: BoS: Urgent !! Serious Linux Security Bug.... (fwd) In-reply-to: Your message of "Mon, 21 Oct 1996 08:08:56 EDT." Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Date: Mon, 21 Oct 1996 07:07:17 -0700 From: Amancio Hasty Sender: owner-hackers@freebsd.org X-Loop: FreeBSD.org Precedence: bulk >From The Desk Of Jeremy Sigmon : > > Date: Sun, 20 Oct 1996 21:14:42 -0400 > From: Eli Burke > To: Multiple recipients of list BUGTRAQ > Subject: Re: BoS: Urgent !! Serious Linux Security Bug.... > > > cy>> > Today we saw an email from Linus Torvalds advising of a probl em > > cy>> >with Linux and ping. Basically you can reboot a linux box remotely i f > > cy>> >some scenario's are right. From what we can tell and this has all be en > > cy>> >verified is: If anyone in the world with a Windows 95 machine can pin g > > cy>> >your Linux box they can potentially reboot that machine.. > > cy>> > > cy>> Yes, but this attack another machines, AIX for example. > > cy>I just tested this against FreeBSD 2.1.5. The machine under attack, > > cy>a 486SX/25, got was for a while but recovered quite nicely. > > > > My Friend tested in this machines: > > > 1) Reboot: OSF/1 3.2C, Solaris2.4 x86 > > > 2) Ignored: *BSD, SunOS4.1.x, IOS, AIX3.2.5, VMS e Solaris 2.4 > > > Sparc, Irix. > > > 3) Respond: M$ e OS/2 > > > 4) Crash: Linux, AIX4, OSF <= 3.2C and AIX3.2.5 on Token-ring. > > I tested this under OSF/1 3.2 and had no problems. Same for DUnix 4.0 , > Ultrix 4.4, Windows NT 4.0 (server and workstation), and FreeBSD 2.1.5. > FreeBSD was the only one that showed any symptoms; the network card stopped > responding for about two minutes, but I could belive that to be the fault of > the lousy intel etherexpress driver. > Is this is a joke? And yes I have had Win95 boxes ping my FreeBSD boxes. Amancio