Vulnerability Development mailing list archives
DOS on inetd w/ nmap
From: shawn.a.clifford () LMCO COM (Clifford, Shawn A)
Date: Mon, 24 Apr 2000 09:45:23 -0400
Hi All, The problem is that inetd will abort when too many connections are made. This is an old problem that appears to still be a problem even on some newer OSes, specifically IRIX (*all* 6.2-6.5, others?), some HP-UX (B.10.20, but only on some machines... dunno why), and of course old SunOS 4.1.3/4.1.4 machines (only some!). You must then log on at the console (unless you had a remote window open to the machine prior to inetd exiting) and either restard inetd or reboot the machine. I was fiddling with the 'httpd_scan.pl' script that I posted a while back, which is predicated on NetCat for the port scanning and for sending http GETs to possible servers, when I thought I would substitute 'nmap' for 'nc' in my script. Nmap is about 4 times faster, as it turns out, for doing port scans, but it has this nasty side-effect. It also seems to be sending data, as it not only crashes inetd on IRIX, but it also crashes some service called 'sgi_fam' with an enormous amount of data. /var/adm/SYSLOG entry: Apr 5 18:30:43 3D:node famd: fd 10 message length 1212498244 bytes exceeds max of 1064. What's doubly annoying about this is that nmap is such a good tool, otherwise, and is being promoted by SANS as a tool of choice. Clearly crashing inetd isn't very subtle. Perhaps there is a way to make nmap "low-and-slow"? Although netcat is much slower, and doesn't have the fingerprinting capability of nmap, I will have to keep using 'nc' for my Web server scans. Regards, -- Shawn
Current thread:
- Re: network appliance..., (continued)
- Re: network appliance... Luiz Eduardo Gava (Apr 12)
- Re: network appliance... Lopez, Joe (Apr 12)
- Re: network appliance... Dom De Vitto (Apr 12)
- Re: network appliance... Hull, Dave (Apr 12)
- Re: network appliance... John Hall (Apr 12)
- Re: network appliance... Paul Taylor (Apr 12)
- Re: network appliance... Crother, Mark (Apr 12)
- Re: network appliance... Marc Slemko (Apr 13)
- Re: network appliance... Stuart Henderson (Apr 17)
- Re: network appliance... James Grinter (Apr 24)
- DOS on inetd w/ nmap Clifford, Shawn A (Apr 24)
- Re: DOS on inetd w/ nmap Roelof Temmingh (Apr 25)
- Re: DOS on inetd w/ nmap LaMont Jones (Apr 25)
- Re: DOS on inetd w/ nmap Richard Johnson (Apr 25)
- Info about Microsoft Exchange application protocol Bobby, Paul (Apr 24)
- Re: Info about Microsoft Exchange application protocol Walter Williams (Apr 24)
- Re: network appliance... Stuart Henderson (Apr 17)