Penetration Testing mailing list archives

Re: John the Ripper - Patch issue with Ubuntu?


From: StaticRez <staticrez () gmail com>
Date: Mon, 9 Jul 2007 17:02:01 -0500

Has anyone else experienced this? if so, please share how to fix the issue.  Is there anyway of turning off stack 
smashing detection, etc?


When compiling try this option:

-fno-stack-protector

I think it should disable SSP during compile.

Also, take a look at this page:
http://www.trl.ibm.com/projects/security/ssp/

StaticRez
--
http://www.staticrez.org
Key Fingerprint :: DC78 5F47 9E33 0B8F 67A4  09C2 0771 FF38 5E29 F338


On 9 Jul 2007 14:52:19 -0000, 09sparky () gmail com <09sparky () gmail com> wrote:
I am wondering if anyone has encountered and overcome this issue:


I am trying to install John v.1.72 on my Ubuntu 7.04 box.  John installs fine.  However, when I install "john-1.7.2-all-7.diff.gz" and 
try to "./john --test " the patch I get the following error: "Benchmarking: Kerberos v5 TGT [krb5 3DES (des3-cbc-sha1)]... *** 
stack smashing detected ***: ./john terminated

Aborted (core dumped)"


Has anyone else experienced this? if so, please share how to fix the issue.  Is there anyway of turning off stack 
smashing detection, etc?


Thanks

Sparky



------------------------------------------------------------------------
This List Sponsored by: Cenzic

Swap Out your SPI or Watchfire app sec solution for
Cenzic's robust, accurate risk assessment and management
solution FREE - limited Time Offer

http://www.cenzic.com/wf-spi
------------------------------------------------------------------------

------------------------------------------------------------------------
This List Sponsored by: Cenzic

Swap Out your SPI or Watchfire app sec solution for
Cenzic's robust, accurate risk assessment and management
solution FREE - limited Time Offer

http://www.cenzic.com/wf-spi
------------------------------------------------------------------------


Current thread: