Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

Re: [SNI-14]: Solaris rpcbind vulnerability
From: jwa () JAMMED COM (James W. Abendschan)
Date: Fri, 6 Jun 1997 02:54:35 -0700


On Thu, 5 Jun 1997, I wrote:
When I saw this a few weeks ago on SNI's web page (it wasn't published
as an advisory, it was published as one of the checks their Ballista tool
performs) I was intrigued, so I sat down and spent some time trying
to exploit this.

By modifying rpcinfo.c to connect to port 32771 and changing the
PMAPPROC_DUMP stuff to work over UDP instead of TCP (clntudp_create),
you can get nicely functional "over-the-packet-filter" rpc dump.

This client is available at

        http://www.jammed.com/~jwa/Security/h_rpcinfo.tar.gz

James

--
James W. Abendschan                                              jwa () jammed com
JAMMED Systems, Inc.                                      http://www.jammed.com
       "Turing," she said.  "You are under arrest."   -- William Gibson



  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]