Vulnerability Development mailing list archives

Re: Apple Mac DoS


From: "Daniel J. Luke" <dluke () GEEKLAIR NET>
Date: Sun, 17 Dec 2000 00:27:17 -0500

On Fri, Dec 15, 2000 at 09:46:18AM -0800, Matteo,Marc A. wrote:
FWIW I just re-installed a Mac OS 9 system from an original iMac OS 9 CD
and then ran Apple's Software Update to get the necessary updates (like
OS 9.0.4).

The Mac OS was updated to 9.0.4 but TCP/IP was NOT automatically updated
to fix the smurf amp (or that high UDP port DoS - I can't remember the
port).

I found that interesting.  I wondow how many Mac users have upgraded
TCP/IP manually?

Check the version number of the TCP/IP control panel.

Apple fixed the DoS issue in MacOS 9 first with a patch, then with an OpenTransport update (Dated 1/04/2000, version 
numbr 2.6).

The 9.0.4 update is dated 4/4/2000. I don't have a copy of TomeViewer handy, but a quick look at the Tome file included 
with the 9.0.4 update seems to indicate that it has OpenTransport related stuff in it.

So, please double-check to see that the TCP/IP control panel is _not_ 2.6.

--
Daniel J. Luke
Head Programmer
CoreComm - East Lansing Office
+========================================================+
| *---------------- dluke () geeklair net ----------------* |
| *-------------- http://www.geeklair.net -------------* |
+========================================================+
|   Opinions expressed are mine and do not necessarily   |
|          reflect the opinions of my employer.          |
+========================================================+


Current thread: