[ntp:security] reproducing mode 7 ping pong

Danny Mayer mayer at ntp.org
Wed Oct 14 04:51:16 UTC 2009


Harlan Stenn wrote:
> Danny,
> 
> You seem to have completely missed the point.
> 
> I asked because other folks will want to run their own tests, to prove
> to themselves that the problem is fixed.

Right. It is important for others to conduct their own tests to verify
the patch is correct. They should not be restrained to only test what I
tested. In fact, it's better if they come up with their own testing.
Dave didn't say whether or not the patch fixed the problem with the
patch he made to cause the attack. I can only say what I did to test the
patch which basically involved making changes to ntpdc to force
bad/invalid packets.

Danny

-- 
This message has been scanned for viruses and
dangerous content by MailScanner, and is
believed to be clean.



More information about the security mailing list