Bugtraq mailing list archives

Re: Overflow in tcplog.c (VD#3)


From: fygrave () SCORPIONS NET (CyberPsychotic)
Date: Thu, 4 Nov 1999 20:49:31 +0500


~:I was just visiting  http://www.echelon.wiretapped.net and downloaded a
~:small file called "tcplog.c" with no author or version stated.  It is for
~:logging connections to your box (linux only).
~:
~:There are some minor coding gripes I could make, but line 107
~:takes a risk with the size of a hostname
~:
~:    98  char *hostlookup(unsigned long int in)
~:    99  {

Yep. I have notified phroid about the problem about a year ago or so,
while was adding some additional features to his code, and he told me he
took care of the problem. I also have added several other features to his
code (and fixed the bug of course). If intersted, you could check the code
out at http://www.kalug.lug.net/tcplogd/.

hope it helps.

Fyodor

--
* Some day this will be a full-fledged user tracking system..
- <linux/sched.h>
                        http://www.kalug.lug.net/fygrave/



Current thread: