Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

Re: Eggrop bug
From: Giuseppe <giusc () gbss it>
Date: Tue, 10 Feb 2004 19:00:24 +0100


Thankfully resync sharing is considered broken and most people do not
use it. Indeed though, this is a bug and thank you for finding it.

that's not exactly true; yes, many people don't use resync, but..

char *share_start(Function *global_funcs)
{
....................
  add_hook(HOOK_SHAREIN, (Function) sharein_mod);
  add_hook(HOOK_MINUTELY, (Function) check_expired_tbufs);
^^^^^^^^^
  add_hook(HOOK_READ_USERFILE, (Function) hook_read_userfile);
....................
}

the function, however, is called minutely, so the bug exists also if resync is disabled. As in previous mail has been already said, check_expired_tbufs() first check for timed out resync buffers, then, "accomplish to handle userfile requests in limbo (that haven't received yet any response from tandem bot)".

Where did you notify eggheads? I seem to be blind while looking for it.

We've notified you at bugs () eggheads org; in a private e-mail i''ve sent to you the response we received.


With respect,
giuseppe




  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]