Re: Simple TCP service can hang a system

Joe Konopka (jkonopka@ITOL.COM)
Tue, 24 Jun 1997 16:16:16 -0500

At 10:06 PM 6/21/97 -0400, you wrote:
>Willy TARREAU enscribed thusly:
>
>> Hi !
>
>> I've noticed that inetd doesn't check the source port for the request
>> to UDP simple services (echo, time, chargen, daytime).
>
>> This means it is possible to build a packet which will look like it comes
>> from one of these ports, to one of these ports. In this case, each UDP
>> response from the simple service will generate a new request to the source
>> port and the system or network can be quickly overloaded.

[parts deleted]

>> I tested Netware Client 32 for DOS/Windows, and it simply hangs. Not tested
>> yet on Win95/NT/Netware...

FYI, under WinNT 4.0, this causes 99% CPU usage in TCPSVCS.EXE, and can be
fixed by stopping and restarting "Simple TCP/IP services".

Return-Path: <NETSPACE.ORG!owner-bugtraq@vec.ccupm.upm.es>
Date: Tue, 24 Jun 1997 08:31:36 -0700
From: Brad Powell <brad.powell@WEST.SUN.COM>
Subject: Re: Fun with devices [was: Re: /dev/tcx0 crashes SunOS 4.1.4 on Sparc
20's]