Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: [Full-Disclosure] Automated ssh scanning |
|---|---|
| Date: | Thu, 26 Aug 2004 18:59:03 -0500 (CDT) |
Howdy Gary,
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Yo All! On Thu, 26 Aug 2004, Deigo Dude wrote:Maybe running this test again, and this time ...No need to run the test again. - From the .history I duplicated this: wget www.bo2k-rulez.net/a Then did this to see the strings in the binary: strings a | less This string looked ineresting: Kernel seems not to be vulnerable A google on that string yields the exloit: http://www.k-otik.com/exploits/12.05.hatorihanzo.c.php A simple exploit for the well known do_brk bug in the Linux kernel...
Cool, I was incrrect in assuning this was a fully patched system and the
compromise likely being an application sploit it appears.
Thanks,
Ron DuFresne
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
"Cutting the space budget really restores my faith in humanity. It
eliminates dreams, goals, and ideals and lets us get straight to the
business of hate, debauchery, and self-annihilation." -- Johnny Hart
***testing, only testing, and damn good at it too!***
OK, so you're a Ph.D. Just don't touch anything.
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
| Previous by Date: | Re: !SPAM! [Full-Disclosure] Automated ssh scanning, sec-focus |
|---|---|
| Next by Date: | Re: [Full-Disclosure] Automated ssh scanning, VeNoMouS |
| Previous by Thread: | Re: [Full-Disclosure] Automated ssh scanning, Gary E. Miller |
| Next by Thread: | Re: [Full-Disclosure] Automated ssh scanning, VeNoMouS |
| Indexes: | [Date] [Thread] [Top] [All Lists] |