Search the web
Sign In
New User? Sign Up
dnrd · DNRD discussion list
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Show off your group to the world. Share a photo of your group with us.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
[grantma@anathoth.gen.nz: Bug#80888: SECURITY - Several multiple bu   Message List  
Reply | Forward Message #183 of 261 |
Re: [dnrd] [grantma@...: Bug#80888: SECURITY - Several multiple buffer overflows in dnrd]

On Fri, 12 Jan 2001, Thomas Schoepf wrote:

> this doesn't sound very good, I'm afraid I've got too little experience with
> network programming. Maybe you both could arrange something?

The potential buffer overflows have been known for a while.

The patches submitted by Wolfgang Zekoll were full of them, but
many people were asking for the functionality that they provided.
I also didn't want to be an 'overbearing' code maintainer. So I
accepted them and thought that I or someone else would get around
to finding & fixing the problems.

In the meantime, exploiting these problems will get you nowhere.
By default, dnrd changes to the "nobody" user. It also does a chroot
to the /etc/dnrd directory, after checking that /etc/dnrd exists
and contains no subdirectories and no executables and is only
writable by root. So the process is jailed. The only thing a cracker
should be able to do by exploiting dnrd is chew up some cpu cycles.

However, I would like to see all the buffer overflows
fixed. Unfortunately, I just don't have the time to work on dnrd
anymore. It really does need a good reorganization.

It's a pretty simple program with functionality that is currently not
available anywhere else. If someone would like to give a shot at
re-writing it, I think everyone would be happy.

Brad Garcia




Fri Jan 12, 2001 4:41 pm

garsh@...
Send Email Send Email

Forward
Message #183 of 261 |
Expand Messages Author Sort by Date

Hello Brad, this doesn't sound very good, I'm afraid I've got too little experience with network programming. Maybe you both could arrange something? Thank...
Thomas Schoepf
schoepf@...
Send Email
Jan 12, 2001
2:35 pm

... The potential buffer overflows have been known for a while. The patches submitted by Wolfgang Zekoll were full of them, but many people were asking for the...
Brad Garcia
garsh@...
Send Email
Jan 12, 2001
3:27 pm
Advanced

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help