Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 4 Dec 2001 13:56:03 +0000
From:      Josh Paetzel <friar_josh@webwarrior.net>
To:        "Riley J. McIntire" <rileyjmc@pacbell.net>
Cc:        Stephen Hovey <shovey@buffnet.net>, FreeBSD Questions <freebsd-questions@FreeBSD.ORG>
Subject:   Re: icmp dos attack?   sshd core dump
Message-ID:  <20011204135602.B446@twincat.vladsempire.net>
In-Reply-To: <NCBBLBILEPCHLFJAPIIPMEBAKFAA.rileyjmc@pacbell.net>; from rileyjmc@pacbell.net on Tue, Dec 04, 2001 at 10:56:09AM -0800
References:  <Pine.BSF.4.05.10112041245260.25439-100000@buffnet11.buffnet.net> <NCBBLBILEPCHLFJAPIIPMEBAKFAA.rileyjmc@pacbell.net>

next in thread | previous in thread | raw e-mail | index | archive | help
> The "OpenSSH UseLogin directive permits privilege escalation advisory",
> if that's what you're referring to, doesn't seem to apply.  It's a hole
> for an otherwise authorized user (hmmm) and only with "UseLogin"
> enabled, which it isn't.
>
> Riley

Correct, this is irrelevent.
 
> > On Tue, 4 Dec 2001, Riley J. McIntire wrote:
> > > This just showed up in a security check output log:
> > > > icmp-response bandwidth limit 240/200 pps
> > > > icmp-response bandwidth limit 213/200 pps
> > > snip pages of this
> > > then
> > > > pid 49374 (sshd), uid 0: exited on signal 11 (core dumped)
> > > > pid 49375 (sshd), uid 0: exited on signal 11 (core dumped)
> > > snip
> > > > pid 49391 (sshd), uid 0: exited on signal 11 (core dumped)
> > > > pid 49394 (sshd), uid 0: exited on signal 11 (core dumped)
> > > > pid 49396 (sshd), uid 0: exited on signal 10 (core dumped)
> > > > pid 49397 (sshd), uid 0: exited on signal 10 (core dumped)
> > > snip
> > > > pid 49465 (sshd), uid 0: exited on signal 10 (core dumped)
> > > > pid 49466 (sshd), uid 0: exited on signal 10 (core dumped)
> > >
> > > Note the change from a sig 11 to 10.
> > >
> > >
> > > A DOS attack?  The machine is up, I can connect via ssh,
> > and I'm a bit
> > > at a loss of what, if anything, to do about this?
> > >
> > > Thanks,
> > >
> > > Riley

What version of FreeBSD are you running?  IIRC, there was a remote 
hole in sshd on 4.3-RELEASE.  Also, what is restarting sshd?  You have 
some sort of cron job running or something?

FFIW, I rarely see ICMP DoS attacks anymore.  Even the MS products 
have been mostly patched against them, and internet routers don't 
forward large ICMP packets for the most part any more.  They are 
pretty worthless for eating bandwidth or fux0ring TCP stacks.  I DO 
see a lot of IGMP based stuff, which is pretty damn effective at 
using up your bandwidth, but doesn't seem to do anything to 
FreeBSD's TCP stack.

Anyways, based on that, it makes it seem local to me, like someone 
is running ping -f as root or something.  Still doesn't make a lot 
of sense that that would cause sshd to dump core.  Seems more 
likely that they are two different things, related perhaps only in 
who is doing them.

Josh


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-questions" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20011204135602.B446>