[tpop3d-discuss]Tpop3d w/ssl crashes after Portscan
Chris Lightfoot
chris at ex-parrot.com
Mon, 23 Feb 2004 12:49:35 +0000
On Sun, Feb 15, 2004 at 10:57:08AM +0100, Martin Schmitt wrote:
> Hey, it's me again! ;-)
>
> Another new observation: I can bring tpop3d down by connecting to the pop3s
> port and then killing the connection. An nmap TCP scan or simple telnet to
> port 995 will do.
>
> Feb 15 10:44:00 vortex tpop3d[11913]: [ID 702911 local0.error] quit: signal 11 post_fork = 0
>
> Again, this is Solaris 8 with OpenSSL 0.9.6c. I can't believe that this
> would-be-DoS hasn't been seen before, so I must be missing something in the
> configuration or elsewhere.
>
> Here's the relevant line from the config.
>
> listen-address: 1.2.3.4 1.2.3.4;tls=immediate,/etc/blah/cert.pem,/etc/blah/key.pem
>
> Any ideas?
Hmm. I can't reproduce this here, but it's on a different
architecture and this may be a race condition anyway, so
reproducing it may not be trivial. Did tpop3d leave a core
file? Do you have gdb or dbx on the machine? A stack trace
from the crash would be most helpful.
--
``It's a small world, but I wouldn't want to have to paint it.''
(Chic Murray)