|
|||||||||||
|
portmon <=1.8 buffer over flow !
From: <auto94042(at)hushmail.com>
Date: Wed Jun 25 2003 - 00:12:56 EDT -----BEGIN PGP SIGNED MESSAGE-----
holo,
i find something when i try portmon out for a ride. this is the home
of portmon -
portmon is software that replaces shell script ping & cron to test the hosts.
this is what i find -
[user@localhost]# export USER=`perl -e 'print "A" x 666'` /* 110 suffice but i like 66 since the vendor is named old nik! ! */ [user@localhost]# /usr/local/bin/portmon -c devilzride.txt Segmentation fault (core dumped)
bad code in portmon.c
err_msg declare as a -
1.8 is no longer suid root ! probably not an exploitation (in <=1.7) becuz there is nothing on heap to write over and n1xo does not like to use the free() (teehe, grep free turns up the dust , who needs the free() anyhow!) .. maybe you find a way ?
USER is not a trusted one and you can spoof the logs or trash the files
by exploit this guy in <1.8:
see - http://www.securityfocus.com/archive/1/325653/2003-06-15/2003-06- 21/0 fix : n1xo said he make a code to fix this one. ask him : Nik Reiman <nik@aboleo.net> greetz :
ts@securityorfice.net is the only one werth the props !
wkYEARECAAYFAj74zFIACgkQarKSBij8yIKdywCfdB0dk3LfrnMXjMYTPT4HSZwGRcoA
n0Z+Y3LYt1T8JKCWRYDCEIThCceo
Free, ultra-private instant messaging with Hush Messenger https://www.hushmail.com/services.php?subloc=messenger&l=434 Big $$$ to be made with the HushMail Affiliate Program: https://www.hushmail.com/about.php?subloc=affiliate&l=427 Received on Wed Jun 25 12:34:41 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:40 EDT |
||||||||||
|
|||||||||||