Re: HACMP and port scans

From: Jordan Klein (haplo@haplo.net)
Date: 09/26/01


Date: Wed, 26 Sep 2001 09:31:28 -0700 (PDT)
From: Jordan Klein <haplo@haplo.net>
To: "Eoin D. Fleming" <rtfm@eircom.net>
Subject: Re: HACMP and port scans
Message-ID: <Pine.BSO.4.33.0109260924170.22634-100000@www.haplo.net>

On Mon, 24 Sep 2001, Eoin D. Fleming wrote:

> It appears that IBM's HACMP 4.4 clustering software can be induced to fail
> simply by port scanning clustered machines, has anyone come accross this
> vulnerability and is there a workaround?
>
> Thanks,
> RT
>

Yes, when I worked at IBM, we found this same problem. We had internal
security groups periodically port scanning our servers and they caused our
HACMP cluster servers to crash, as a result.

I don't remember all the details, as I didn't personally work with HACMP.
However, a good friend did and told me all about it. I believe IBM has
some patches that can fix this problem.

I think it's somehow simulating a failover signal, but not correctly, so
causing a kernel panic or something.

-- 
Jordan Klein                                         haplo@haplo.net
gpg fingerprint = 3D15 2822 F5A9 AED4 A66C  48EF 0A21 39CB A5BA 8C5B
        You have moved your mouse.  Windows will now reboot.



Relevant Pages

  • FW: Port scan causing system crashes
    ... Port scan causing system crashes ... We can help with the HACMP Cluster issue. ... BUGTRAQ Vulnerability 3358, "IBM HACMP Port Scan Denial of Service ...
    (Pen-Test)
  • Re: HACMP and port scans
    ... Subject: HACMP and port scans ... > It appears that IBM's HACMP 4.4 clustering software can be induced to ... > fail simply by port scanning clustered machines, ... quiet, and we worked with Compaq to develop a patch. ...
    (Bugtraq)
  • Re: Built-in dual ethernet adapter & disk controllers (in 570) and HACMP
    ... I think the probability that your controller integrated chipset is ... the fact that you're only using one port host side ... Main spof is you have only on SCSI chain. ... HACMP cant help you in this case. ...
    (comp.unix.aix)
  • Re: Failover in seconds
    ... > doesn't address the underlying problem that the server to which requests ... > where VMS Clusters, with their Connection Manager and cluster-wide file ... I should point out that IBM has had a clustering product for some ... Originally known as HACMP/6000, later renamed to HACMP. ...
    (comp.os.vms)
  • RE: HACMP and port scans
    ... Subject: HACMP and port scans ... Maintenance Level 7 on AIX 4.3.3 seemed to fix the problem for us. ...
    (Bugtraq)