Full Disclosure mailing list archives

Re: SQL Slammer - lessons learned


From: Niels Bakker <niels=netsys () bakker net>
Date: Wed, 5 Feb 2003 19:48:34 +0100

I wrote:

So, given (1434 - 1023 - 1) other applications that use UDP active, or
that many outstanding queries, BIND may very well end up using UDP port
  ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
1434 for a query packet.

Which turns out to be incorrect - BIND allocates one socket only for
outgoing queries, but no entry in /etc/services will keep an operating
system from allocating a port randomly.


        -- Niels.

-- 
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: