Re: serious telnet bug; is it just me? (fwd)

Chris B. Wilson, VectorNet (cbw@vector.net)
Fri, 8 Sep 1995 18:02:12 -0400 (EDT)

On Fri, 8 Sep 1995, Brian 'MegaZone' Bikowicz wrote:

> No, that is not what I said. I said I wouldn't/don't personally think of
> it as a bug, it is a console feature. But I also understand the worry, and
> I've already (as in the moment I reporodced it) sent the info up the tree to
> be worked on.

well, actually it *is* what you said, maybe just not what you meant :)..

> 1. There is a workaround (which I would think anyone worried about security
> would have done already) - packet filtering.

true..

> 2. In *very* brief testing it didn't reboot a unit running a new beta.

Thats lovely, doesn't help us much (yet:)..

> 3. This 'bug' has been around nigh unto forever - how many reports have there
> been of PMs being reset willy-nilly with it?

This 'feature' was just 'discovered' recently it would seem.. Luckially
the people seeing this 'panic' are seeing it, and know how to handle
things until an update is released. How many people are running USR Total
Control cards and don't read this list (yeah, it works on them too)? In
any case, now that its known, expect more calls to tech support about
"spontaneous reboots"..

> I'm a bit amused by the mad panic, like it needs to be fixed yesterday or
> the world will end. Calm down, breathe deep, relax - the odds are extremely
> low that someone will decide to exploit this out of the blue. We know about
> it, and it will be addressed.
> Life is to short to get too worried about something like this. It can be
> prevented already.

It's Friday, we've found something that can be reeeeally annoying if the
users discover it, and we're in an underpaid, overstressed business. What
exactly were you expecting :)

Happy weekend..
Chris

------------------------------------------------------------------------------
Chris B. Wilson Office (904) 375-8658
Director of Network Operations Digital Pager (904) 339-7982
Gateway Telecommunications/VectorNet cbw@vector.net
------------------------------------------------------------------------------