Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Fri, 12 Dec 2014 15:33:24 +0100
From: Pierre Schweitzer <pierre@...ctos.org>
To: oss-security@...ts.openwall.com
Subject: Re: CVE request: denial of service in suricata

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On 12/12/2014 02:58 PM, Victor Julien wrote:
> 
> Btw, 2 other fixes directly in suri are somewhat related:
> 
> https://github.com/inliniac/suricata/commit/4eff27c108ecbcd4fc61453590f0a3d3bcf9105d
>
> 
https://github.com/inliniac/suricata/commit/2c9ce634a9667ba89b22d953e3102d35badd1912
> 
> What is the policy of crashing when out of memory? On most systems
> this will likely be an effective DoS even w/o crash. If you can
> force your IDS to go into swap it's pretty much ineffective.

Not sure about that one...

Especially with Out-Of-Memory killer which is on most servers and that
will actually kill your daemons before they can crash due to the lack
of memory.

Or you can even disable your server swap abilities (vm.swappiness) to
always keep all your applications in memory, which will trigger OOM
killer even faster.
- -- 
Pierre Schweitzer <pierre@...ctos.org>
System & Network Administrator
Senior Kernel Developer
ReactOS Deutschland e.V.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBAgAGBQJUivy0AAoJEHVFVWw9WFsLjasP/06zTGgC6gAmfHCQJAWYV3cD
IK5HEwbbeTR7/J/FhYF+hdKBvEJ0LJ+dUQ5VOvGbP+l2KtKQ3twPnmzdZxGbsIUQ
5spdu1ci83QUgjvTQenYPquJW3bTI8bqytQYoMjQmtxMrYCycvduKRU9zGDItO8P
ew4JVaJSkofLSheM7WNRmkCk/vxifrxLMh2QKsqK5kwFLZgCOUvdTDxqpE5KEDN0
PDXngToNj5ua6oDX3TsOey7Cpp528RKj9YDiG9lnhySwvL8/TsB+deWMUOGdKs5Q
3O+5fQCJ9loFgbYGtwndOv8ML3oRrzNmPxCLOrWekNyyfHA8njvoCXLZhRAbSp58
qcv14HOvg4wT5ORjgMeHngrcXnl39ykHIGQTTTTbhFIfVioT4ehnoEEm+iML71H/
G3DadE2enh4tXWH4eYAJbabUEALD9ZdtDbtUUv04jhGjaRx3CKnlZCq1t14hwfLZ
sFgtWanbQQQooqGpXCQuXC1IgdDIljnc02rBtZsNqASKbz6fr0rP485cRQyNsHZm
AbZUzG8SuQxDG8zM08t2T21HUOHCqFWMwM5mFfhtup8VSW4BVo/zqEJGw9DZ67EF
/Xu1r6HoF/hkxMxVrNHNHEs1/h2prGk5b/REpNueLgVPZRKYpMQC1QnkAElmMD4X
w9PzbIdC0i52kBvRIL7+
=mYid
-----END PGP SIGNATURE-----

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.