Date: Wed, 19 Apr 2000 09:17:49 -0700 From: Mike Ireton <mike@BAYOFFICE.NET> Subject: Adtran DoS To: BUGTRAQ@SECURITYFOCUS.COM Hi Gang, While testing some new gear, I found a serious problem with the Adtran MX2800 M13 Multiplexer. This device aggregates up to 28 T1's onto a Channelized DS3 interface and is primarlly used in cases where you've got a lot of T1's. The unit I have has dual redundant controller cards so I don't know if this problem would show up with the single card version. But anyways, the problem is simply that it will crash and restart if you ping flood it's ethernet interface. After 15-20 seconds of ping -f, it just dies and then re-initializes. That will take all circuits out of service until it comes back up. Pretty, huh? I contacted Adtran about this and they didn't sound suprised at all. In fact I got the distinct impression that they knew about this problem before hand. I haven't seen any action taken on my ticket so I don't know if they are planning a firmware upgrade or not to address this, but for now my response has been to make sure the box is not acessible over the network and I hope others will do likewise. -- Mike Ireton Senior Systems Engineer Bay Office Net - http://www.bayoffice.net Voice (415) 643-8700 "Where do you want to go today?" Fax (415) 643-8777 With Linux, I'm already there....