TUCoPS :: SunOS/Solaris :: solfingr.txt

Solaris 2.5.1 and 2.6 fingerd contains a finger forwarding DoS.


[ http://www.rootshell.com/ ]

Date:         Wed, 5 Aug 1998 11:39:02 -0400
From:         Fiji <jfay@STETSON.EDU>
Subject:      Solaris 2.5.1/2.6 fingerd bug

Well it seems that Sun reintroduced the finger forwarding  and finger DoS
into Solaris 2.5.1 and 2.6.

try finger @host@host@host....145 times.... This should run the # of
processes in excess of 1500 and shoot the system load up to at least 13.5.

You can also do a finger @hosta@hostb where hostb is a machine running 2.5.1
or 2.6. Now this has not been confirmed on Solaris (x86). The bug id is
4161606 but yet there is no patch available as of today.

-Fiji

----------------------------------------------------------------------------

Date:         Thu, 6 Aug 1998 20:29:49 +0200
From:         Casper Dik <casper@HOLLAND.SUN.COM>
Subject:      Re: Solaris 2.5.1/2.6 fingerd bug

>Fiji (jfay) wrote:
>> try finger @host@host@host....145 times.... This should run the # of
>> processes in excess of 1500 and shoot the system load up to at least 13.5.
>>
>> You can also do a finger @hosta@hostb where hostb is a machine running
>> 2.5.1 or 2.6. Now this has not been confirmed on Solaris (x86). The bug id
>> is 4161606 but yet there is no patch available as of today.
>
>Yep, same thing happens for x86 running 2.6.


It's not new nor reintroduced.  It's been in fingerd forever.

Casper

TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2024 AOH