|
|||||||||||
|
Re: NSLOOKUP.EXE
From: Nexus <nexus(at)patrol.i-way.co.uk>
Date: Fri Mar 21 2003 - 05:15:41 EST
I get an Input too long error if run through cmd.exe, eg. c:\>nslookup.exe AAAAA[..], but if I run nslookup with no args, then request AAA[..]AAA it gives the 0x41414141 memory error. If I give nslookup a much larger amount of A's, the response is: (null) dns.server.net then crashes. -Patrick This has been around for a while - I seem to recall looking at this a couple of years ago but since the overflow (on quick inspection) looked tricky to exploit *and* it's the client end that overflows, I didn't bother with it. There is no local priv escalation and you would need control of the victims' DNS servers - in which case, you can do far more interesting things that this ;-) The only use I could think of it was when you are in a restricted environment and can only use sanctioned commands, with nslookup being one of them. Cheers. Received on Fri Mar 21 18:05:51 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:38 EDT |
||||||||||
|
|||||||||||