[WarpCast] OS/2 TCP/IP Denial Of Service attack - 6/15/99 |
Inet.Mail 1.3 -- The best mail server on OS/2 just got better! Audit Capabilities, More Spam Control, Improved Performance Visit us at http://www.hethmon.com/inetmail.html for full details. A free update for current users. ****************************** WarpCast ****************************** Source: Eirik Overby (ltning@mo.himolde.no) Moderator: Dirk Terrell (admin@os2ss.com) ********************************************************************** On the late evening of friday 11th of June, we at Pepper Head discovered a DoS attack that could crash any OS/2 machine running TCP/IP 4.1 or higher, that is, MPTS 5.x or 6.x. This includes also OS/2 Warp Server for e-business. The exploit was first discovered on Linux 2.2.x kernels on the 1st of June, and when we tried it on one of our servers, it died instantly with a trap 000e. We found this error to be serious enough to want to try alerting IBM as soon as possible. Spending the next 24 hours on the phone to various IBM offices around the globe, we were finally able to get in touch with someone that really understood the severity of the problem. So they started working on the problem on saturday, and today we got the fix - directly from the developers. This fix has not yet been posted to IBM's official sites, but until it is, it can be found on this address: ftp://hobbes.nmsu.edu/pub/incoming/icmpfix.zip ---------------------------------------------------------------------- To subscribe, unsubscribe, or for more information on WarpCast, visit: http://www.warpcast.com/ ----------------------------------------------------------------------