From owner-FreeBSD-net-jp@jp.freebsd.org  Wed Aug 20 17:49:31 1997
Received: by jaz.jp.freebsd.org (8.8.7+2.7Wbeta6/8.7.3) id RAA28114
	Wed, 20 Aug 1997 17:49:31 +0900 (JST)
Received: by jaz.jp.freebsd.org (8.8.7+2.7Wbeta6/8.7.3) with ESMTP id RAA28106
	for <FreeBSD-net-jp@jp.freebsd.org>; Wed, 20 Aug 1997 17:49:28 +0900 (JST)
Received: from uucp3.iij.ad.jp (uucp3.iij.ad.jp [202.232.2.203]) by mail0.iij.ad.jp (8.8.5+2.7Wbeta5/3.5Wpl4-MAIL) with SMTP id RAA28480 for <FreeBSD-net-jp@jp.freebsd.org>; Wed, 20 Aug 1997 17:49:27 +0900 (JST)
Received: (from uucp@localhost) by uucp3.iij.ad.jp (8.6.12+2.4W/3.3W9-UUCP) with UUCP id RAA28767 for FreeBSD-net-jp@jp.freebsd.org; Wed, 20 Aug 1997 17:49:25 +0900
Received: (qmail 13361 invoked by uid 1000); 20 Aug 1997 08:48:54 -0000
Message-ID: <19970820084854.13360.qmail@reseau.toyonaka.osaka.jp>
Date: Wed, 20 Aug 1997 17:48:54 +0900 (JST)
From: Kenji Rikitake <kenji@reseau.toyonaka.osaka.jp>
X-Sender: kenji@reseau.reseau.rcac.tdi.co.jp
To: FreeBSD-net-jp@jp.freebsd.org
In-Reply-To: <19970819130805L.matusita@ics.es.osaka-u.ac.jp>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=ISO-2022-JP
Reply-To: FreeBSD-net-jp@jp.freebsd.org
Precedence: list
X-Distribute: distribute [version 2.1 (Alpha) patchlevel=20]
X-Sequence: FreeBSD-net-jp 97
Subject: [FreeBSD-net-jp 97] Re: DoS attack and the solution: tcpserver or a modified inetd?
Errors-To: owner-FreeBSD-net-jp@jp.freebsd.org
Sender: owner-FreeBSD-net-jp@jp.freebsd.org

On Tue, 19 Aug 1997, Makoto MATSUSHITA wrote:
> $B7k6IA4It$4$j$4$j:Y$+$/$d$m$&$H;W$C$?$i(B($B4{B8$N(B FreeBSD $BImB0(B) inetd $B$G$O(B
> $B?I$$!$$H$$$($P$^$"$=$&$J$N$@$H$O;W$o$l$^$9!%(B

$B$^$"$"$^$j0l2U=j$K=8Cf$7$F$7$^$&$H!"@_Dj$9$k$H$3$m$O0l$D$G:Q$`$1$I$b!"2?$r(B
$B$d$C$F$$$k$N$+$o$+$j$K$/$/$J$k$H$$$&$N$O$"$j$^$9!#(B

> $B!&(B-a option $B$r;H$($P(B bind $B$9$k(B address $B$O=q$1$k$i$7$$$N$G!$(Bbind $B$7$?$$(B 
>   address $B$N?t$@$1(B inetd $B$rF0$+$;$PNI$$(B (Well, it's simple:)

$B$&$&$`!"A4It$N%5!<%S%9$,F1$8%"%I%l%9$K(Bbind()$B$5$l$A$c$&$s$G$7$g$&$+!#(B
$B$3$l$O;?H]N>O@$"$j$=$&$G$9$M$(!#(B

> $B!&(Bident $B$rC!$$$F$b5$5Y$a$K$7$+$J$i$J$$$H;W$($P!$$G$-$J$+$C$?$+$i$H$$$C(B
>   $B$FHa$7$^$J$/$F$b$^$"$$$$(B(Windows95 $B$N7W;;5!$r(B ident $B$GC!$$$FLa$C$F$-(B
>   $B$?J8;zNs$r8+$F!$2?$N0UL#$,$"$k(B?:)

tcpserver$B$G$O(Bident$B$O;H$o$J$$$h$&$K$b$G$-$^$9!#(B

> kenji> DoS$B967b$K$O(Binetd$B$G$b;R6!$N?t$N@)8B$r$7$F$d$l$P$=$l$J$j$NBP:v$O(B
> kenji> $B$G$-$k!"$H$$$&$3$H$G$9$M!#(B
> 
> process table $B$rNO$$$C$Q$$$G$+$/$7$FBP=h!$$H$+(B :-p

$B$$$d!"LdBj$K$J$k$N$O!"3F%W%m%;%9$,@jM-$9$k%a%b%j6u4V$NJ}$@$H;W$&$s$G$9$h!#(B
$B$b$A$m$s(Bprocess table$BBg$-$/$7$F$*$/$3$H$OI,MW$G$9$,!#(B

$B$H$3$m$G!"(Binetd$B$O!"Nc$N(B

	service/protocol server failing (looping), service terminated.

$B$H$$$&8=>]$,5/$-$k$H%5!<%S%9$r0lDj;~4V5Y;_$7$F$7$^$&!"$H$$$&5!G=(B($B%P%0$G$O(B
$B$J$$(B:))$B$,$"$j$^$9$,!"$3$&$$$&8=>]$O(Btcpserver$B$G$O5/$-$J$$$h$&$G$9!#(B
($BK;$7$$%5!<%P$@$H!"$3$NBT$A;~4V$OCWL?E*$K$J$j$+$M$J$$$H;W$$$^$9$,!"$I$&$G(B
$B$7$g$&!#(B)

// Kenji Rikitake <kenji@reseau.toyonaka.osaka.jp> <kenji@rcac.tdi.co.jp>
// An equal opportunistic encryptor. WWW: http://www.nn.iij4u.or.jp/~kenji/

