Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security FullDisclosure
[Top] [All Lists]

RE: [Full-disclosure] Cisco IOS Shellcode Presentation

Subject: RE: [Full-disclosure] Cisco IOS Shellcode Presentation
Date: Fri, 29 Jul 2005 15:02:59 -0400 (EDT)
On Fri, 29 Jul 2005, Eric Lauzon wrote:

: 
:So mutch fuss....its all so new ..
:
:
:http://www.phrack.org/phrack/56/p56-0x0a
:
:
:-elz

I don't get your point; it obviously seems you're trying to be sarcastic.

I think, if you realize what you're talking about, the point of the talk 
was the idea of reliably being able to exploit a IOS vulnerability.  
Reliably meaning having the cisco box not reboot on you (or other various 
scenarios that could occur).

Gaius has some good information there, but there's a difference between 
being on a router and plugging in backdoor code and actually being able to 
get onto the router via an exploit.

So what was the key point?  CHECK HEAPS -- the idle proc that kicks in to 
validate heap management structures.  Think about malloc() bugs (double 
free()'s and stuff) that were talked about a few years back... Those were 
easier to exploit b/c they didn't have a check heaps code that kicks in...

If you don't understand the last paragraph, then, please stop trying to 
post technical arguments on this subject.


Cheers,
Andrew
--
Andrew R. Reiter
arr@watson.org
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

<Prev in Thread] Current Thread [Next in Thread>