Insecure hardware (was Re: gets(3) nonsense)

Brandon S. Allbery allbery at ncoast.UUCP
Sun Dec 4 03:25:22 AEST 1988


As quoted from <14733 at mimsy.UUCP> by chris at mimsy.UUCP (Chris Torek):
+---------------
| (It is worth noting that the fingerd attack was applied only to VAXen.)
| 
> (deleted; "wwww" is the "worm address" where the worm had to run)
|
| I will, however, note that any number of local changes might have
| moved the address `wwww' far enough to foil the attack.  One could
+---------------

>From what I've read, the fingerd attack was applied to Suns as well -- but
the "wwww" address *was* sufficiently wrong, so an infected fingerd simply
dumped core.

++Brandon
-- 
Brandon S. Allbery, comp.sources.misc moderator and one admin of ncoast PA UN*X
uunet!hal.cwru.edu!ncoast!allbery  <PREFERRED!>	    ncoast!allbery at hal.cwru.edu
allberyb at skybridge.sdi.cwru.edu	      <ALSO>		   allbery at uunet.uu.net
comp.sources.misc is moving off ncoast -- please do NOT send submissions direct
      Send comp.sources.misc submissions to comp-sources-misc@<backbone>.



More information about the Comp.lang.c mailing list