Bugtraq mailing list archives
Re: Veritas BackupExec (remote DoS)
From: Jonah Kowall <jkowall () PSTEERING COM>
Date: Mon, 15 Jan 2001 15:57:40 -0500
Doesn't the agent only work on backup exec enterprise editions? That's what I'm using it with. If you tell them you are using the enterprise edition, maybe you can get a different response? Tell them you are evaluating it if need be. I have connected to it, and disconnected, and I didn't see it stop responding. I have also opened 3 separate connections, and found it took all three simultaneously. Backup Exec -- Unix Agent, Version 5.01 Revision 5.023 Copyright 1999 VERITAS Software Corporation. All Rights Reserved. This is the version of the Linux agent I am running on redhat 6.2. -----Original Message----- From: oh3mqu+bugtraq () TERAFLOPS COM [mailto:oh3mqu+bugtraq () TERAFLOPS COM] Sent: Monday, January 15, 2001 8:25 AM To: BUGTRAQ () SECURITYFOCUS COM Subject: Veritas BackupExec (remote DoS) Hello, I am using Backup system from Veritas Software (http://www.veritas.com/) and its Linux agent. That agent is listening TCP-socket (8192 in my system) and if someone makes connection to that socket, but do not send anything to it, the agent hangs forever, even if you close that connection. For example portscanners make it to hang. I think that the problem is that the software is not using select() function calls before read() calls and it is not using threads either. I reported that to the Veritas and they replied "Unfortunately our Backup Exec Desktop Products do not support backing up Linux machines. I'm afraid we would be unable to assist you in this instance, however thank you for your interest." -- Ari Saastamoinen oh3mqu+bugtraq () teraflops com
Current thread:
- Re: Veritas BackupExec (remote DoS) Jonah Kowall (Jan 16)
- Re: Veritas BackupExec (remote DoS) Jason Griffiths (Jan 17)
- Re: Veritas BackupExec (remote DoS) Matthew Keller (Jan 17)
- <Possible follow-ups>
- Re: Veritas BackupExec (remote DoS) Michael Owen (Jan 16)
- Re: Veritas BackupExec (remote DoS) Jason Griffiths (Jan 17)