Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

RE: NSLOOKUP.EXE

From: Brett Moore <brett(at)softwarecreations.co.nz>
Date: Thu Mar 20 2003 - 18:56:57 EST


Hi

To do it from the command prompt. you must echo to a file and then redirect.

ie:
nslookup < foo

where foo contains the long string ending with a <CR>.

Because this is read error, it may be possible to insert valid values to read
untill you hit some code that does a write.

Longer strings overflow a strcpy or multibytetowide copy and result in a write error
but because the buffer ends at non writeable memory, I couldn't see anything important
been overwritten. Perhaps though.

nslookup ver 5.0.2195.4985

Brett

Do you need help?X

-----Original Message-----
From: Blue Boar [mailto:BlueBoar@thievco.com] Sent: Friday, March 21, 2003 9:07 AM
To: Patrick Webster
Cc: vuln-dev@securityfocus.com
Subject: Re: NSLOOKUP.EXE

Patrick Webster wrote:
> Can you do anything interesting with this?:
AAAA
>
>

AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAA
>
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAA
> AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA

If you have to manually type all the A's, then probably not. Maybe if someone did something silly like make a CGI script that calls nslookup.exe directly with user input.

What OS are you testing on? It looks like it's fixed in XP:

C:\winxp\system32>nslookup
Default Server: dns1.snfcca.sbcglobal.net Address: 206.13.28.12

 >

AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
*** Input is too long
 >

                                        BB Received on Fri Mar 21 13:26:20 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:38 EDT

Do you need more help?X

Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library