Bugtraq mailing list archives

remote Pine <= 4.56 exploit fully automatic


From: sorbo <sorbox () yahoo com>
Date: Mon, 15 Sep 2003 16:14:17 +0200

Ok here it is
Remote pine exploit
quite efficient since no "real offsets are needed" especially in the
first method of exploitation

Worx against grsec high security with random stack with "hard" method
since it is a return to libc tested vs slackware grsec

portbind on 6682 with FULL therminal support i.e. launch bx from ur exp =D

autodiscovers targets/offsets needed

redhat works too but only "easy" method... because of a pop ebp before a
ret.. there is no leave

worm can easily b made especially with "bruteforce" with about 99%
success!!

have fun =P



sorry i forgot to attach code ;D

Attachment: sorpine.c
Description:


Current thread: