freebsd-nq/usr.sbin
Poul-Henning Kamp 02c589d9e9 This may apply to all known versions of inetd.
For a tcp/nowait connection, inetd invokes accept(2) for
each pending connection; this call returns a file descriptor
associated with the new connection.

Twelve years ago, code was added to inetd to detect "failing
servers".  The heuristic that identifies a failing server is
one that has been invoked a large number of times over some
specified interval (e.g., more than 128 ftp services started
in 60 seconds may flag the ftp service as "failing").  These
compile-time constants vary depending on vendor.

The problem is that, when a failing server is detected, the
code neglects to close the file descriptor returned by the
accept(2).

Security-Implications:
I suppose someone with ample free time could orchestrate an
attack buy pummeling services until the inetd process finally
runs out of file descriptors thus rendering inetd useless to
any new connections that require a new descriptor.

PR:		7286
Reviewed by:	phk
Submitted by:	Jeff Forys <jeff@forys.cranbury.nj.us>
1998-07-22 05:53:53 +00:00
..
ac /var/log/wtmp entries for ptys are treated differently in ac, since 1998-07-02 05:34:08 +00:00
accton
adduser Always ask for homedir. 1998-06-07 18:38:32 +00:00
amd Don't assume that time_t is long. 1998-06-29 17:25:46 +00:00
apm
apmconf
arp
bad144
bootparamd #include <arpa/inet.h> for inet_* definitions. 1998-06-12 14:39:00 +00:00
cdcontrol Mention all the environment variables that can be used 1998-06-13 19:28:51 +00:00
chkgrp Inserted missing .Bl in the FILES section. 1998-07-14 07:55:27 +00:00
chown
chroot
ckdist
config Dump out ISA device resources for alpha. 1998-07-21 21:47:51 +00:00
cron Fixed printf format errors. 1998-07-06 20:28:08 +00:00
crunch
ctm Spellint fixes. 1998-06-10 12:33:41 +00:00
dev_mkdb
diskpart
dpt
edquota
fdcontrol
fdformat
fdwrite Typo. 1998-06-27 21:29:35 +00:00
inetd This may apply to all known versions of inetd. 1998-07-22 05:53:53 +00:00
iostat
ipfstat
ipftest
ipmon
ipnat
ipresend
ipsend
iptest
IPXrouted
kbdcontrol
kbdmap
kernbb
keyadmin
keyserv
kgmon
kvm_mkdb Always support an elf kernel when given one. 1998-06-12 16:25:18 +00:00
lpr Remove -Werror from CFLAGS on i386 because with -nostdinc gcc spits 1998-06-11 03:53:23 +00:00
lptcontrol
manctl
mixer
mount_portalfs Correct use of .Nm. Spelling. Add rcsid and remove unused #includes. 1998-07-06 07:19:27 +00:00
mountd Correct improper use of .Sm. Document -d flag. Correct use of .Nm. Remove 1998-07-15 06:21:41 +00:00
moused Reviewed by: Amancio 1998-06-14 20:05:27 +00:00
mptable
mrouted Don't assume that time_t is long. Fixed printf format errors (don't 1998-06-29 17:51:39 +00:00
mtest
mtree There is no need to make nochange imply ignore as well. 1998-06-10 06:45:08 +00:00
named bsd.dep.mk doesn't know about -idirafter, and doesn't parse -I the 1998-06-11 10:42:58 +00:00
named.reload
named.restart
natd Fix inconsistent port numbering in man page. 1998-07-15 03:32:45 +00:00
ncrcontrol Remove printing of variable "reselect" which is not really maintained 1998-07-12 20:30:11 +00:00
ndc
newsyslog Add optional config file field: signal number to send (defaulted to HUP) 1998-06-09 18:24:04 +00:00
nfsd Do not dot terminate syslog() string. Remove unused #includes. Add rcsid. -Wall. 1998-07-15 06:33:15 +00:00
nologin Add Id. .Nm nologin -> .Nm. 1998-07-15 06:37:07 +00:00
nslookup
nsupdate
pccard
pciconf
pcvt $@ deprecated, use long form. 1998-06-09 05:14:43 +00:00
periodic
pkg_install Clarify "Cannot delete file as directory" errmessage. 1998-07-18 22:19:11 +00:00
pnpinfo
portmap
ppp Add missing braces - without them, the IP & label were mis-selected 1998-07-19 21:07:24 +00:00
pppctl
pppd Forgot to resync the RELNOTES to 2.3.5 1998-06-23 21:41:58 +00:00
pppstats Remove illegal ".Nm". This file is still using -man, not -mdoc. 1998-07-09 04:53:11 +00:00
procctl
pstat Fixed printf format errors. 1998-07-06 20:28:08 +00:00
pw Fix race condition in pw caused by multiple instances of pwd_mkdb being 1998-07-16 17:18:25 +00:00
pwd_mkdb Fix usage string 1998-06-09 20:19:59 +00:00
quot
quotaon
rarpd
repquota Make it compatible with long usernames 1998-06-14 22:56:31 +00:00
rmt
rndcontrol
rpc.lockd
rpc.statd
rpc.yppasswdd
rpc.ypupdated
rpc.ypxfrd
rtprio
rwhod
sa
sade MF22: various fixes for new XFree86 dist and cdrom warnings. 1998-07-21 06:44:42 +00:00
sendmail $@ is deprecated, use longer forms of single char macros 1998-06-09 05:36:48 +00:00
sgsc
sicontrol
sliplogin
slstat Removed bogus #ifdef INET - <net/if_slvar.h> no longer depends on it. 1998-07-06 20:09:36 +00:00
spkrtest
spray
stallion
sysctl Document sef's recent changes in the corefile naming. 1998-07-21 18:16:16 +00:00
sysinstall MF22: various fixes for new XFree86 dist and cdrom warnings. 1998-07-21 06:44:42 +00:00
syslogd Fixed printf format errors. 1998-07-06 20:28:08 +00:00
tcpdump
timed Don't assume that time_t is long. Fixed printf format errors. 1998-06-29 18:12:08 +00:00
traceroute $@ is deprecated, use longer forms of single char macros 1998-06-09 05:36:48 +00:00
trpt
tzsetup
vidcontrol ioctl() request args are unsigned longs, so don't attempt to store 1998-07-14 10:32:27 +00:00
vipw
vnconfig
watch
wlconfig
wormcontrol
xntpd #include <arpa/inet.h> instead of rolling own prototype. 1998-06-12 14:58:03 +00:00
xten
yp_mkdb
ypbind
yppoll
yppush Don't assume that time_t is long. 1998-06-29 18:15:21 +00:00
ypserv Allow blank lines in /var/yp/securenets. 1998-07-15 11:56:28 +00:00
ypset
zic
Makefile Drop mkdosfs (replaced by newfs_msdos). 1998-07-19 13:41:08 +00:00
Makefile.inc