Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Vulnerability Development: ICQ Guestbook Exploit ?

ICQ Guestbook Exploit ?

From: Maxime Rousseau <mrousseau_at_LABCAL.COM>
Date: Thu, 1 Jun 2000 09:41:44 -0400

Hi list,

Someone (meliksah_at_meliksah.net) in NTBugtraq has pointed out a bug in
the impressively bad programmed ICQ, about all versions. It involves the
personal web server feature of ICQ and overflowing the 'name' paramter
of the guestbook.cgi. Has anyone gave a shot on this and see if its
exploitable? The original poster makes no statements regarding the
possible impact of this. As i am not very familiar with owning cgi stuff
perhaps someone could enlighten me as the usefullness of this (read: do
i have to fear armageddon). Mayhaps someone like rfp or some
web-oriented person...

Thx,
M.
Received on Jun 01 2000

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos