Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 15 Mar 2001 21:59:13 -0800
From:      Kris Kennaway <kris@obsecurity.org>
To:        "Michael A. Dickerson" <mikey@singingtree.com>
Cc:        freebsd-security@freebsd.org
Subject:   Re: Multiple vendors FTP denial of service (fwd)
Message-ID:  <20010315215913.A70990@mollari.cthul.hu>
In-Reply-To: <004b01c0ada9$99f7b540$db9497cf@singingtree.com>; from mikey@singingtree.com on Thu, Mar 15, 2001 at 03:42:29PM -0800
References:  <98righ$100l$1@FreeBSD.csie.NCTU.edu.tw> <004b01c0ada9$99f7b540$db9497cf@singingtree.com>

next in thread | previous in thread | raw e-mail | index | archive | help

--a8Wt8u1KmwUX3Y2C
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Thu, Mar 15, 2001 at 03:42:29PM -0800, Michael A. Dickerson wrote:
> > 4.1 from Aug 10th is hurt by it.
> >
> >          ---Mike
> >
>=20
> So is 4.3-beta (otherwise known as 4-stable) from March 8.  ftpd uses 100%
> cpu and memory use grows until the kernel runs out of swap space and star=
ts
> killing processes.  This was an ftp connection with a regular username and
> password, in an average home directory.

I'm pretty sure (but haven't tested) that resource limits will prevent
this problem.  Your ftpd shouldn't be using large amount of memory
under normal operating procedures, so you can set those to reasonable
values and not suffer any ill effects.

Kris

--a8Wt8u1KmwUX3Y2C
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.4 (FreeBSD)
Comment: For info see http://www.gnupg.org

iD8DBQE6sauwWry0BWjoQKURAgE4AKCnmhjKbrNZCIMikQJWUftK81880ACeMt5a
pb6xBdAHKw1FylymJOF7y3k=
=YHjb
-----END PGP SIGNATURE-----

--a8Wt8u1KmwUX3Y2C--

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20010315215913.A70990>