Re: Why Satan kills informix processes ?
Posted in 1998
From my email archives for April 1995, which is when Satan was first
released...
>From: Mark Sigler <msigler@informix.com>
>Subject: [WARNING]SATAN can crash Online! (fwd)
>Date: Sat, 8 Apr 95 10:29:39 EDT
>
>For those of you who have not heard about 'SATAN', it is a piece of
>public domain software that is designed to identify security holes.
>It is based on a Mosiac interface with a rules-based application that
>executes scripts that test a particular service port (like sendmail)
>for generally known weaknesses (older sendmail versions have many).
>
>It was developed by the former Network Administrator from Silicon Graphics
>to check their network for potential security problems.
>
>This application is very similar to the 'COPS' system which uses 'KUANG'
>for the rules parsing. So, there have been many public domain products
>like this available for some time. The beauty and the danger is that
>due to the GUI interface, it is pretty easy for a novice wanna-be hacker.
>
>Expect to hear more about this in the coming months...
>
>--
>
>Mark Sigler
>Client Services Engineer
>Informix Software, Inc.
>Fort Lauderdale, FL
>
>--
>>
>> I ran SATAN on my UNIX server that has Informix ONLINE 7.1 on it. I had it
>> do a heavy scan and it crashed Online with the following error message:
>> ^^^^^^^
>>
>> ---online.log---
>> 11:34:24 Checkpoint Completed: duration was 0 seconds.
>> 11:34:36 Assert Failed: Internal Error - Segmentation Violation
>> 11:34:36 Who: Thread(12, soctcplst, 0, 1)
>> 11:34:36 Results: OnLine must abort
>> 11:34:36 Action: Reinitialize shared memory
>> 11:34:36 See Also: , shmem.32eca6.0
>> 11:34:49 rsdebug.c, line 3557, thread 12, proc id 586, Segmentation Violation.
>> 11:34:49 PANIC: Attempting to bring system down
>> ---------------->>
>> Of course this problem will only occur if you have a TCP entry in your
>> sqlhosts file with something like the following:
>>
>> ---sqlhosts---
>> hostname onsoctcp hostname online
>> -------------->>
>> Just thought you all ought to know :-) I think this is something we should
>> all be extremely worried about!
>> --
>> +-----------------------------+--------------------------------------------+
>> | BRIAN K. HOLMAN | E-Mail: brian_holman@byu.edu |
>> | Programmer/Systems Analyst | URL: http://lib1.byu.edu/staff/bkh/ |
>> | Library Information Systems | Mail: 2330 HBLL, Provo, UT 84602 |
>> | Brigham Young University | Phone: (801) 378-8162 |
>> +-----------------------------+--------------------------------------------+
>From: bkh@lib1.byu.edu (Brian K. Holman)
>Subject: Re: [WARNING]SATAN can crash Online!
>Date: 8 Apr 1995 17:46:14 GMT
>X-Informix-List-Id: <news.12873>
>
>Richard Spitz (spitz@GANS2X.ana.med.uni-muenchen.de) wrote:
>: What is SATAN?
>
>SATAN (Security Administrator Tool for Analyzing Networks) remotely probes
>systems via the network and stores its findings in a database. It tests for
>known security holes such as sendmail problems, etc. It also tests the
>range of TCP and UDP ports, NFS, and so forth.
>--
>+-----------------------------+--------------------------------------------+
>| BRIAN K. HOLMAN | E-Mail: brian_holman@byu.edu |
>| Programmer/Systems Analyst | URL: http://lib1.byu.edu/staff/bkh/ |
>| Library Information Systems | Mail: 2330 HBLL, Provo, UT 84602 |
>| Brigham Young University | Phone: (801) 378-8162 |
>+-----------------------------+--------------------------------------------+
Yours,
Jonathan Leffler (jleffler@informix.com) #include <witticism.h>
Guardian of DBD::Informix v0.60 -- http://www.perl.com/CPAN
Informix IDN for D4GL & Linux -- http://www.informix.com/idn