Subject: Re: inetd limits
To: der Mouse <mouse@Rodents.Montreal.QC.CA>
From: Manuel Bouyer <bouyer@antioche.eu.org>
List: tech-net
Date: 12/02/2001 00:24:25
On Sat, Dec 01, 2001 at 06:18:27PM -0500, der Mouse wrote:
> > How about adding a concurrency limit in inetd so that only a
> > specified number of simultaneous invocations of each service may be
> > started?
> 
> Seems to be to me _asking_ for a DoS attack (though I suppose such
> attacks are possible anyway).

Yes, of course: just make more than the allowed connections per
second. Just ran into this with rquotad on my NFS server :)

--
Manuel Bouyer <bouyer@antioche.eu.org>
--