Subject: Re: heads up, ftp attacks
To: Wolfgang Rupprecht <wolfgang@wsrcc.com>
From: Andrew Gillham <gillhaa@ghost.whirlpool.com>
List: current-users
Date: 02/26/1998 11:17:23
> Here is write-up of a security problem I had here on Feb 10, 1998 on
> my netbsd/x86 box.  It involved the ftp that comes with krb5.  Folks
> may want to double and triple check their ftpd setup.
> 
> 	http://www.wsrcc.com/wolfgang/ftpattack/
> 
> -wolfgang

Yeah, the "Warez boyz" got you..

FWIW, why do you think your NetBSD box crashed?  Shouldn't the TCP
state engine handle the problem?  Or was it just the fact that so many
ftp processes were forked you ran out of swap?  

-Andrew
-- 
-----------------------------------------------------------------
Andrew Gillham                            | This space left blank
gillham@whirlpool.com                     | inadvertently.
I speak for myself, not for my employer.  | Contact the publisher.