Bugtraq mailing list archives
Re: Internet Worm
From: ccsis () bath ac uk (Icarus Sparry)
Date: Tue, 18 Oct 1994 21:23:59 +0100
Sun (at least in SunOS 4) didn't do any "mucking about" with libresolv and YP in libc.
The resolv+ package shows exactly how to replace routines in the libc.so/sa files such that the gethostbyname()/gethostbyaddr() lookups happen via the DNS (or NIS, or just the /etc/host file, it depends on how you configure things).
Jim
I think you will find that Sun put a double lookup into gethostbyaddr(), to prevent spoofing. This of course goes against the Unix spirit of 'do one thing only, but do it well'. This double lookup can be enabled with the resolv+ library by using the 'nospoof' command in its configuration file. You can argue that you want this always, but if so you should write a 'getvalidatedhostbyaddr()' routine on top of gethostbyaddr(), and not corrupt the original routine. Programs like rlogind & rshd should then call this new routine.
Current thread:
- PLEASE UNSUBSCRIBE ME, (continued)
- PLEASE UNSUBSCRIBE ME Mark McPherson (Oct 17)
- Re: Internet Worm Pat Myrto (Oct 17)
- Re: Internet Worm David Miller (Oct 17)
- PLEASE UNSUBSCRIBE Vatsal P. Sonecha (Oct 17)
- Re: Internet Worm Fred Kuhns (Oct 18)
- Internet Worm Source Code Michael S. Hines (Oct 17)
- rhosts (+ REQUEST SNMP bug) James Seng (Oct 17)
- Re: Internet Worm George Hodson (Oct 17)
- Re: Internet Worm Mark W. Eichin (Oct 18)
- Re: Internet Worm jim () Tadpole COM (Oct 18)
- Re: Internet Worm Icarus Sparry (Oct 18)
- Re: Internet Worm F. L. Charles Seeger III (Oct 18)
- Re: Internet Worm jim () Tadpole COM (Oct 18)
- Re: Internet Worm F. L. Charles Seeger III (Oct 19)
- Re: Internet Worm Darragh Nagle (Oct 19)
- Re: Internet Worm Gene Spafford (Oct 19)
- Re: Internet Worm jim () Tadpole COM (Oct 19)
- Re: Internet Worm F. L. Charles Seeger III (Oct 20)
- Re: Internet Worm smb () research att com (Oct 19)
- R utilities, addresses, etc. Charles Howes (Oct 20)
- Re: R utilities, addresses, etc. Alexander L. Haiut (Oct 20)
- R utilities, addresses, etc. Charles Howes (Oct 20)
(Thread continues...)