Re: Something new? bind dos? exploit?

From: Dan Merillat (dan_at_merillat.org)
Date: 02/17/04

  • Next message: Access Denied: "Re: buddylinks worm"
    Date: 17 Feb 2004 20:20:41 -0000
    To: incidents@securityfocus.com
    
    
    ('binary' encoding is not supported, stored as-is) In-Reply-To: <402CBDE3.3010308@avwashington.com>

    (Pardon in advance for formatting problems, I'm stuck posting via the web)

    Chip Mefford writes:

    >Feb 13 06:55:40 hostname named[12631]: socket.c:1100: unexpected error:
    >Feb 13 06:55:40 hostname named[12631]: internal_send:
    >244.254.254.254#53: Invalid argument

    While people have pointed out that this is basically
    just a misconfigured NS record (even if deliberate) it does act as a DOS against bind9 boxes.

    Hitting a bind9/linux2.4 box with queries for something in proxies.monkeys.com causes it to spew error messages to the logs, eating lots of CPU and eventually crashing bind9. The problem is that it's not treating it as an unreachable host, but reporting the error and attempting again.

    ---------------------------------------------------------------------------
    Free trial: Astaro Security Linux -- firewall with Spam/Virus Protection

    Protect your network with the comprehensive security solution that
    integrates six applications for ease of use and lower TCO.

    Firewall - Virus protection - Spam protection - URL blocking - VPN
    - Wireless security.

    Download 30-day evaluation at:
    http://www.astaro.com/php/contact/securityfocus.php
    ----------------------------------------------------------------------------


  • Next message: Access Denied: "Re: buddylinks worm"

    Relevant Pages

    • [NT] Microsoft Visual C++ 8.0 Standard Library Time Functions Invalid Assertion DoS (Problem 3000)
      ... Get your security news from a reliable source. ... Microsoft Visual C++ 8.0 Standard Library Time Functions Invalid Assertion ... - Second vendor notification ...
      (Securiteam)
    • Error convert applying security template
      ... security template as follows. ... The data is invalid, ... Unable to establish connection with global catalog. ...
      (microsoft.public.win2000.active_directory)
    • Re: cant connect to wireless router with F7
      ... dell inspiron 9200 with linksys pcmcia card ... i've used this pcmcia card successfully with linksys routers for a ... Encryption key:xxxxxxxxxx Security mode:restricted ... Rx invalid nwid:0 Rx invalid crypt:11306 Rx invalid frag:0 ...
      (Fedora)
    • RE: WebDav Worm?
      ... I've seen the exact same pattern from 7 different source IPs in the ... All source IPs appear to be DSL or cable modem, ... Astaro Security Linux -- firewall with Spam/Virus Protection ...
      (Incidents)
    • Re: Changing permission recursively
      ... the security ID structure is invalid. ... In my Path I have long folder names, e.g.: ... John John. ...
      (microsoft.public.win2000.general)