Full Disclosure mailing list archives

Re: FIXED CODE - IIS 6 Remote Buffer OverflowExploit(was broken)


From: Cody Hatch <bytejump () gmail com>
Date: Thu, 21 Apr 2005 21:36:00 +0000

Try running John the Ripper on the file. LOL.

Cody

On 4/21/05, Tim O'Guin <timoguin () gmail com> wrote:
Yah... You can take that back now as of 3:04 CST.  hehe.

On 4/21/05, bkfsec <bkfsec () sdf lonestar org> wrote:

I haven't seen any evidence as of yet that anyone ran this code on a
segment connected to the network (seeing as I haven't seen any passwd or
shadow files posted to the list...) indicating that most people probably
ran it (if anyone ran it at all) from test machines.

                      -Barry

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Current thread: