Three Dead Protocols
blog.annharter.com
blog.annharter.com
Even for something as simple as QOTD the implementer has to consider things like message lengths and interpret terms like "should" (a recommendation, not an obligatory condition for compliance.) Observe that the standard also doesn't mandate that the message must change only once per day, so the implementation presented is compliant. :-)
For TCP Echo, because TCP is a stream-oriented protocol and AFAIK since you can't actually send and receive simultaneously in code - it's always read or write - the question of how much to echo back, and after how long, is also something to consider. Theoretically, an echo server could wait to send until several GB of data were received or the connection is closed, buffering the data limitlessly, and still be compliant. This also shows the importance of being clear and precise when writing standards or protocol specifications in general, should you ever need to do so.
Sure you can, there's no problem having a thread writing while another reads in parallel.
Print server management was done through a Telnet interface. We also supported LPD which was one of the stupider protocols ever to see the light of day.
I added a QOTD service to the firmware as an easter egg.
I'm going to go soak my teeth now.
Try to get an IP packet that's not TCP, UDP, or ICMP through a consumer level Internet provider.
I can't speak for other countries.
I'd be interested in hearing if there were any ISPs that didn't just forward GRE packets using normal IP routing conventions.
Used to be like this on Demon, Virgin Media and Easynet. The latter fixed their stuff circa 2007 however.
On the server, I ran "socat IP4-RECV:254 STDOUT", and on the client I ran "socat STDIN IP4-SENDTO:theservername:254", then typed at the client. Came through just fine.
https://www.shodan.io/report/9xshqrdb
Many of these old protocols don't die easily and tend to linger around forever. Maybe there's a nostalgic element to keeping them alive for sysadmins :)
Well.
In a decade of doing pen tests in a mix of professionally capacity and informally for friends, I have never seen echo or daytime, and saw QOTD once on a test box on the CS department of a university.
Of course, working with organizations who sought out someone to do a pentest probably self-selects out networks which would have this kind of nonsense. Reducing attack surface by turning off services or blocking them at various firewalls has been standard operating procedure for IT for at least 2 decades.
Well, who am I kidding? This is the same IANA that used to hand out humongous blocks of IPv4 addresses to anyone who asked.
Should we try to deprecate dead protocols so that low ports can be put into better use? Or have we come to expect that all new technologies will simply reuse ports 80 & 443, so we have no need to set aside new well-known ports anymore?
I suspect firewalls blocking everything but ports 80 and 443 has a lot more to do with why so many services these days are being stacked on top of them. I used to run a SOCKSv5 SSH tunnel home when I worked for a more restrictive employer, and of course I stuck it on port 443.
Maybe throw in some fuzzing: accept-and-respond-with-gibberish-default.
accept-and-spam-MX-record-always
https://en.wikipedia.org/wiki/Common_Address_Redundancy_Prot...
Honestly, with 65K+ ports, why would people want to re-use old ones ?
Not that this makes it impossible, just more difficult.
RFC 2616 was published in June 1999.
I don't know what Sir Tim was doing in May 1983, but I'm pretty sure he wasn't writing an RFC for a protocol that he wouldn't invent for six more years.
You have to go into the config and add a key (!) to actually be able to access it. And worse, there's no way I've seen to actually just straight disable the "feature". You have to add an individual port, or a range of ports, or a comma-separated list of ports or ranges.
(For those wondering, it's "network.security.ports.banned.override", with a value of a port, or range, or comma-separated list of ports or ranges. For example: "7,13,17".)
Once you do, it works fine.
$ nc zx2c4.com 17
Source here: http://git.zx2c4.com/mulder-listen-daemon/tree/mulderd.cI also run a toy telnet server:
$ telnet zx2c4.com
:PThe parameters to Thread.new are just passed straight through to the block.
I suspect that is one of the many reasons that is a dead protocol.
[1] https://github.com/foliveira/echo-is-not-dead
Ahh, Vim. It makes me happy to know that more seasoned developers than myself have issues with it as well.
I wonder if I could do that with Google App Engine talking to the blog and just picking random posts.
[1] http://q4td.blogspot.com/ http://www.twitter.com/q4td https://plus.google.com/u/0/110672212432591877153/posts http://www.facebook.com/quote4theday
A bit of an aside, how many people still use plain netcat? I switched to ncat years ago, and haven't looked back.
random_index = rand(quotes_array.length + 1)
@quote_body = quotes_array[random_index]["Quote"]
@quote_author = quotes_array[random_index]["Author"]
https://github.com/theaisforannie/qotd/blob/master/qotd.rb#L...Gracias Señor@!