What happens when you don't validate/scrub data on input from whois

Eric Kuhnke eric.kuhnke at gmail.com
Tue Sep 28 18:57:48 UTC 2021


https://research.securitum.com/fail2ban-remote-code-execution/

What happens if you put the following in your whois entry:

drop table prefixes;

Or anything similar...

https://xkcd.com/327/
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mailman.nanog.org/pipermail/nanog/attachments/20210928/13787217/attachment.html>


More information about the NANOG mailing list