[PATCH] telnetd max active sessions

Denys Vlasenko vda.linux at googlemail.com
Fri Nov 30 06:02:20 UTC 2007


On Thursday 29 November 2007 00:28, Roberto A. Foglietta wrote:
> 2007/11/28, Denys Vlasenko <vda.linux at googlemail.com>:
> > On Tuesday 27 November 2007 05:30, Roberto A. Foglietta wrote:
> > > Hi,
> > >
> > >  in order to limit the max number of telnetd accpeted sessions apply
> > > this patch.
> >
> > Instead of adding this to each networking applet, I propose using
> > inetd's connection limiting, or use this applet + telnetd in inetd mode:
>
>  I cannot use inetd or perhaps not everywhere. Unlimited sessions
> could allow a password cracking brute force attack on embedded system.
> That is the reason because I decided to develop this patch. I just
> upgraded from 1.0.1 to 1.2.2.1 but in this phase I cannot propose
> further versions. I need to use legacy version because after
> deployment system firmware would not be upgradeable for a long time.

Patches are uploaded here

http://busybox.net/downloads/fixes-1.2.2.1-foglietta/

--
vda



More information about the busybox mailing list