Re: 3Ware 3DM denial of service attack

From: Jason Giglio (jgiglio@netmar.com)
Date: 01/30/03

  • Next message: bugzilla@redhat.com: "[RHSA-2003:020-10] Updated kerberos packages fix vulnerability in ftp client"
    Date: Thu, 30 Jan 2003 14:36:51 -0500
    From: Jason Giglio <jgiglio@netmar.com>
    To: "Neulinger, Nathan" <nneul@umr.edu>
    
    

    On Thu, 30 Jan 2003 09:57:37 -0600
    "Neulinger, Nathan" <nneul@umr.edu> wrote:

    > I've reported this to 3ware at least twice, and never received any
    > response. Previously I didn't have a test case other than "run a nessus
    > scan against the host". I've narrowed it down to a reproducible minimum
    > test case now.
    >

    I can confirm that a Nessus scan does indeed crash 3DM, at least up to
    version 1.13.00.019.

    -- 
    Jason Giglio
    IT Coordinator
    Smyth Bedford, VA, USA
    Phone: 540-586-2311x113
    


    Relevant Pages

    • Re: [Full-Disclosure] Nessus stores credentials in plain text
      ... > I have posted this issue to a couple entities like bugtraq and CERT ... > with no response. ... What you call credentials are nothing more than system data for Nessus ...
      (Full-Disclosure)
    • Re: Newbie Security Question
      ... > I had to hard boot it and all seems fine now, how do you block attacks from ... Nessus isn't intended to crash the machine, ... always going to give different results than scanning from another ...
      (comp.unix.bsd.freebsd.misc)