BugTraq
RE: Solaris 10 Port Stealing Vulnerability Mar 30 2011 09:12PM
Chris O'Regan (chris encs concordia ca) (1 replies)
Re: Solaris 10 Port Stealing Vulnerability Mar 31 2011 03:18PM
Casper Dik Oracle COM

>Imagine if you find a Solaris system running a web server that has a
>remote exploit which allows for the execution of arbitrary code. If the
>web server happens to be listening on the wildcard interface than you
>can very easily insert your own web server in front of it!

There SO_EXCLBIND setsockopt in Solaris which protects hijacking the port.

Casper

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus