[tpop3d-discuss]Tpop3d w/ssl crashes after Portscan

Chris Lightfoot chris at ex-parrot.com
Mon, 23 Feb 2004 12:49:35 +0000


On Sun, Feb 15, 2004 at 10:57:08AM +0100, Martin Schmitt wrote:
> Hey, it's me again! ;-)
> 
> Another new observation: I can bring tpop3d down by connecting to the pop3s
> port and then killing the connection. An nmap TCP scan or simple telnet to
> port 995 will do.
> 
> Feb 15 10:44:00 vortex tpop3d[11913]: [ID 702911 local0.error] quit: signal 11 post_fork = 0
> 
> Again, this is Solaris 8 with OpenSSL 0.9.6c. I can't believe that this
> would-be-DoS hasn't been seen before, so I must be missing something in the
> configuration or elsewhere.
> 
> Here's the relevant line from the config. 
> 
> listen-address:  1.2.3.4 1.2.3.4;tls=immediate,/etc/blah/cert.pem,/etc/blah/key.pem
> 
> Any ideas? 

Hmm. I can't reproduce this here, but it's on a different
architecture and this may be a race condition anyway, so
reproducing it may not be trivial. Did tpop3d leave a core
file? Do you have gdb or dbx on the machine? A stack trace
from the crash would be most helpful.

-- 
``It's a small world, but I wouldn't want to have to paint it.''
  (Chic Murray)