lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite for Android: free password hash cracker in your pocket
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <200307230349.h6N3n4qj004074@turing-police.cc.vt.edu>
From: Valdis.Kletnieks at vt.edu (Valdis.Kletnieks@...edu)
Subject: R7-0015: Multiple Vulnerabilities Apple QuickTime/Darwin Streaming Server 

On Tue, 22 Jul 2003 19:36:09 PDT, security snot said:
> How are denial of service attacks against a media server security issues?

If somebody can send you a packet that takes out your server, and then do it
again 5 mins later when the server reboots, lather, rinse, repeat, it's a
security issue.

If somebody can send you a low-bandwidth stream of packets that make your
server work WAY too hard, so that the expensive server that's supposed to be
handling 500 simultaneous clients is dropping users at 75, it's a security
issue.

If you don't believe it now, wait till you're the sysadmin of the server that's
being attacked, and you tell the VP that you're dead in the water because some
script kiddie is packeting you.  And after the VP finishes with you, you'll
either be a believer or unemployed. ;)

-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 226 bytes
Desc: not available
Url : http://lists.grok.org.uk/pipermail/full-disclosure/attachments/20030722/d33b7880/attachment.bin

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ