Re: Linux still vulnerable to DoS attacks through ppp link

Riley Williams (rhw@BigFoot.Com)
Sun, 17 Jan 1999 15:54:04 +0000 (GMT)


Hi Matt, Alex.

>> About a few minutes ago whilst I was on IRC, some braindead script
>> kiddie managed to $$$$ up my ppp connect such that I was left
>> hanging online,

> Are you sure it's a Linux problem? or is your modem subsceptible to
> the "old school DoS" described in the thread starting
> http://www.geek-girl.com/bugtraq/1998_3/0916.html

> (ie. send the string +++ATZ to your modem and watch it hang up.
> send +++ on it's own and it will do as you described above - won't
> hang up yet because it's in command mode)

If that's the problem, then there IS a fix for it - most modems have
an S-register where the character used for switching to command mode
is set, and if you tweak that to some other character, preferably one
that's rarely repeated, it will help.

There's also an S-register that sets the delay required either side of
that sequence for it to be recognised, and if you also set that rather
higher than the default 60 seconds, that helps even more...

>> Is there any methods or ways I can set a watch and log whatever is
>> happening so I can post a more detailed report to get it fixed?

> How about tcpdump -i ppp0 ?

I'd also check for susceptibility for the above as well...

> P.S. lin-ker lag seems to be down to less than a minute atm.. woo!

At last !!!

Best wishes from Riley.

---
 * ftp://ftp.MemAlpha.cx/pub/rhw/Linux
 * http://www.MemAlpha.cx/~rhw/kernel.versions.html

- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.rutgers.edu Please read the FAQ at http://www.tux.org/lkml/