RE: [Full-Disclosure] C99 Security Alert-Old-New-Who-Cares :) - (:

From: Schmehl, Paul L (pauls_at_utdallas.edu)
Date: 05/30/03

  • Next message: mattmurphy_at_kc.rr.com: "Re: [Full-Disclosure] NSFOCUS SA2003-05: Microsoft IIS ssinc.dllOver-long Filename Buffer Overflow Vulnerability"
    To: <full-disclosure@lists.netsys.com>
    Date: Fri, 30 May 2003 11:10:48 -0500
    

    Normally I wouldn't bother pointing this stuff out, but if you're going
    to accuse other people of having less than a third grade
    education....well, people who throw stones shouldn't live in glass
    houses....

    operation systems? NOT SUFFICANT??? AS POSSIABLE??? Intgreaty???

    Maybe you should consider finishing school yourself, before you
    criticize others.

    Paul Schmehl (pauls@utdallas.edu)
    Adjunct Information Security Officer
    The University of Texas at Dallas
    AVIEN Founding Member
    http://www.utdallas.edu/~pauls/

    -----Original Message-----
    From: democow .... [mailto:democow8086@hotmail.com]
    Sent: Thursday, May 29, 2003 10:06 PM
    To: full-disclosure@lists.netsys.com
    Subject: [Full-Disclosure] C99 Security Alert-Old-New-Who-Cares :) - (:

    SECURITY VUNERABILITY ALERT:

    hello,
    as a new white-hat hacker i would like to help the information security
    industry by posting a new vulnerability in the the linux operating
    system(this vulnerability may be present in many other operation systems

    depending on their implementation of the c)

    i am posting this vulnerability to help the security community support
    itself in these troubled times, i know how hard it is for you to improve
    you
    image in their media these days.. so i would like you to scam a few more

    companies with some penetration tests.. and your "consulting" services

    AND PLEASE POST AS MANY EXPLOITS AS YOU CAN BASED ON THE FOLLOWING
    INFORMATION... AS JUST INFORMATION ON THIS PROBLEM IS NOT SUFFICANT TO
    PLEASE SOME PEOPLE... ALSO I WOULD LIKE AS MANY CONSULTING COMPANIES
    AS
    POSSIABLE TO OFFER SERVICES USING THEM FOR THEIR OWN PROFIT.. I WOULD
    HATE
    TO SEE ANYONE HAVE TO LEARN ANYTHING BUT HOW TO COMPILE A PROGRAM..(i do
    not
    consider writing a report something that anyone who has a education
    beyond
    that of the 3rd grade something that has to be learned by the corporate
    scam-artist )

    -------|LOCATED IN /lib/string.c|-----

    char * strcpy(char * dest,const char *src)
    {
            char *tmp = dest;

          [1] while ((*dest++ = *src++) != '\0')
                    /* nothing */;
            return tmp;
    }

    as you can see at line [1] there is no length/intgreaty checking as src
    is
    being inserted into dest

    SOLUTION:
    there is no solution to this problem if there were, one would be common
    by
    now.. as we all know now there are no true standards worth following
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: mattmurphy_at_kc.rr.com: "Re: [Full-Disclosure] NSFOCUS SA2003-05: Microsoft IIS ssinc.dllOver-long Filename Buffer Overflow Vulnerability"

    Relevant Pages

    • Re: What is the point here?
      ... You do a very good job of describing the purpose of vulnerability ... disclosure as a means of achieving better information security. ... those flaws are being exploited to cause your customers harm? ...
      (Bugtraq)
    • SecurityFocus Microsoft Newsletter #165
      ... Tenable Security ... distribute, manage, and communicate vulnerability and intrusion detection ... Microsoft Internet Explorer MHTML Forced File Execution Vuln... ...
      (Focus-Microsoft)
    • SecurityFocus Microsoft Newsletter #174
      ... This issue sponsored by: Tenable Network Security ... the worlds only 100% passive vulnerability ... MICROSOFT VULNERABILITY SUMMARY ... Novell Netware Enterprise Web Server Multiple Vulnerabilitie... ...
      (Focus-Microsoft)
    • [NT] Cumulative Security Update for Internet Explorer (MS04-038)
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Get your security news from a reliable source. ... CSS Heap Memory Corruption Vulnerability, ... Microsoft Windows NT Server 4.0 Terminal Server Edition Service Pack 6 ...
      (Securiteam)
    • SecurityFocus Microsoft Newsletter #171
      ... Better Management for Network Security ... GoodTech Telnet Server Remote Denial Of Service Vulnerabilit... ... ASPApp PortalAPP Remote User Database Access Vulnerability ...
      (Focus-Microsoft)