Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 13 Jul 1998 09:30:39 +0100
From:      "Neil Long" <neil.long@oucs.ox.ac.uk>
To:        Hallam Oaks P/L list account <maillist@oaks.com.au>, "freebsd-security@FreeBSD.ORG" <freebsd-security@FreeBSD.ORG>
Subject:   Re: DNS zone xfers from random(?) sites
Message-ID:  <980713093039.ZM5809@ratbert.oucs.ox.ac.uk>
In-Reply-To: Hallam Oaks P/L list account <maillist@oaks.com.au> "DNS zone xfers from random(?) sites" (Jul 10,  9:59pm)
References:  <199807101158.VAA15030@mail.aussie.org>

next in thread | previous in thread | raw e-mail | index | archive | help
-----BEGIN PGP SIGNED MESSAGE-----

I would be willing to bet a beer that this is a direct consequence of 
the release of 'mscan' - check out www.rootshell.com or just about any 
exploit site.

This nifty little tool is a pain in the ... and can be set to scan all 
hosts by country, etc - so the transfers are probably arisng when they 
scan .au and it goes and gets all the hosts by zone transfers (or other 
means). 

The tool will then scan for most of the current known holes by OS 
(determined primarily by the telnet banner content - hint!), we see 
lots of them. Attempts to use the results of the probes (it does not 
attack the weaknesses found) may then come from the same host doing 
the scan or some other one.

I am a little surprised that CERT/CC haven't released a bulletin on 
this yet.

Best advice I can offer is to get it and use it on your own domain to 
see what is 'on offer' and then change the default telnetd banner 
login which limits the impact of this particular tool - there are of 
course lots of other ways of getting the host OS on defualt setups.

Regards
Neil

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
*  Dr Neil J Long, Computing Services, University of Oxford
*               Banbury Road, Oxford, OX2 6NN, UK
*  Tel: +44 1865 273232      Fax: +44 1865 273275
*  EMail:       Neil.Long@computing-services.oxford.ac.uk  

-----BEGIN PGP SIGNATURE-----
Version: 2.6.3i
Charset: noconv

iQCVAwUBNanFpqNsRd57vOpJAQF82gQA5QAJuwyjwQSPOtk2aj5bahCZDvC6YnOF
JIYB5B3xh4TuWFs86hc/HHtUP4N7Ly6Swt3T2jr0M+dKgb43uiH1a8seuw38CSTI
Jeuv2219Ij/jVb+mx3eSyv9uadmum1sqg4NkoYUBonOiVwFxlyh/Xya+GniyXaeq
nB2GGZM+H+8=
=ANcz
-----END PGP SIGNATURE-----

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe security" in the body of the message



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?980713093039.ZM5809>