[24148] in bugtraq

home help back first fref pref prev next nref lref last post

nmap vs. inetd on Caldera (ex-SCO) OpenServer, Re: DoS bug on Tru64

daemon@ATHENA.MIT.EDU (Bela Lubkin)
Wed Feb 6 19:22:06 2002

Date: Tue, 5 Feb 2002 01:34:46 -0800
From: Bela Lubkin <belal@caldera.com>
To: bugtraq@securityfocus.com
Message-ID: <20020205013446.B2391@mammoth.ca.caldera.com>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <01C1AAFB.5E82ACE0.jrose@byrnecut.com.au>; from jrose@byrnecut.com.au on Fri, Feb 01, 2002 at 08:35:13AM -0000

Jethro Rose wrote:

> I am unsure if it is a known problem (I'm fairly new to this list), however 
> I managed to cause our SCO OpenServer 5.0 box to exhibit similar behavior, 
> by simply running nmap (out of curiosity) against it with:
> 
> nmap -v -v -O <ip of sco box>
> 
> This was some time ago - I just put it down to SCO's dodgy per-connection 
> licensing scheme and made a mental note to not scan that box - we didn't 
> have a console available (only way into it via telnetd), so I couldn't 
> verify whether or not it was only inetd that crashed.

See ftp://stage.caldera.com/pub/security/openserver/CSSA-2001-SCO.33/
for a corrected inetd binary.

"5.0" isn't a precise OpenServer version number, versions have been
5.0.0, 5.0.2, 5.0.4, 5.0.5, 5.0.6.  Run `uname -X` to get the precise
version.

The above fix is labeled for 5.0.5 only (fixed in 5.0.6), but I believe
the binary will work on 5.0.0 and later if you install a shared library
update, ftp://stage.caldera.com/pub/security/openserver/CSSA-2001-SCO.10/.

>Bela<

home help back first fref pref prev next nref lref last post