.:[ packet storm ]:.
                           
the new hotness
the new hotness

 Section:  .. / groups / gobbles  /

Page 1 of 1
<< 1 >> Files 1 - 3 of 3
Currently sorted by: Last ModifiedSort By: File Name, File Size

 ///  File Name: GOBBLES-own-ipppd.c
Description:
Gobbles exploit for ipppd which is part of the isdn4linux-utils package and is part of the default install of many linux distributions. Under Suse 8.0, ipppd is installed suid root but can only be run by users in the group "dialout". The exploit works on a syslog(3) format string problem: syslog(LOG_NOTICE,devstr). This code is normally only reached with a valid device string but if you feed ipppd a devicename that is >= 256 bytes it will merrily proceed to log this string using the faulty syslog(3) call. Subsequently handing over root access to the machine.
Author:Gobbles Security
Homepage:http://www.bugtraq.org
File Size:6911
Last Modified:Aug 11 01:48:29 2002
MD5 Checksum:5fcb7f50a51088c23c51cfb1b614c767

 ///  File Name: own-ettercap.c
Description:
Ettercap v0.6.2 local root format string exploit. Works if the administrator made Ettercap SUID.
Author:Alicia
Homepage:http://www.bugtraq.org
File Size:7673
Last Modified:Dec 9 04:50:36 2001
MD5 Checksum:d6e5951f7604f7851edf50f992c03724

 ///  File Name: fingerd-cgi.txt
Description:
Berkeley finger.cgi has a remote command execution vulnerability because it does not strip out newlines.
Homepage:http://www.bugtraq.org/
File Size:6089
Last Modified:Nov 22 08:12:30 2001
MD5 Checksum:9684aed3ac871b146dc84de43c08404f