Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 157507 - net-analyzer/ike-scan: information leak
Summary: net-analyzer/ike-scan: information leak
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Other
: High minor
Assignee: Gentoo Security
URL: http://bugs.debian.org/cgi-bin/bugrep...
Whiteboard: ~4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2006-12-08 03:49 UTC by Richard van den Berg
Modified: 2006-12-14 07:56 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Richard van den Berg 2006-12-08 03:49:59 UTC
User-Agent:       Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1) Gecko/20061010 Firefox/2.0
Build Identifier: 

ike-scan will track
it's usage by doing a gethostbyname() to a special address. Sneaky
bastards. See http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=327220 for
detailed information.

Please build ike-scan on Gentoo using the configure --disable-lookup option

Reproducible: Always

Steps to Reproduce:
1. Run "tcpdump -n port 53"
2. Run ike-scan against any host
3. See how ike-scan phones home using a DNS request

Actual Results:  
ike-scan does a dns lookup to ike-scan-target.test.nta-monitor.com

Expected Results:  
Nothing. I don't want my software to let anyone know I am using it.
Comment 1 Jakub Moc (RETIRED) gentoo-dev 2006-12-08 03:52:56 UTC
Shrug... 

security, you want this one?
Comment 2 Tavis Ormandy (RETIRED) gentoo-dev 2006-12-08 04:13:07 UTC
Yes, that must be removed asap.

Netmon team: please provide an updated ebuild that disables this "feature".
Comment 3 Marcelo Goes (RETIRED) gentoo-dev 2006-12-08 20:59:58 UTC
Done, thanks!
Comment 4 Matthias Geerdsen (RETIRED) gentoo-dev 2006-12-14 07:56:20 UTC
hm... probably a rating of 4 (if at all)

anyways, only marked ~arch -> closing