Full Disclosure mailing list archives

Re: Linux + bash and a silver fork


From: liquidfish <liquidfish () gmail com>
Date: Mon, 27 Aug 2007 11:20:17 -0700

I hope fork bombs aren't coming as news or a surprise to anyone on this list
as they are neither new nor surprising. Check out limits.conf for a way to
limit the impact of such an attack (restrict the DoS to a single user
account or service rather than the entire system)

On 8/27/07, Niko Lilja <niko.lilja () gmail com> wrote:

Well, as has been said when you realize the truth that there is no spoon,
but instead there'll be a
bunch of forks instead, at least in linux on bash shell, tested ubuntu and
RHEL this far.

By throwing a nice piece of line code as a command in bash shell (normal
user) you can pretty much
crash the whole server cause denial of service by giving a command in
bash:

:() { :&:; } ;:


Almost as the ascii would be smiling..

- N


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Current thread: