Re: [Full-Disclosure] Resources for exploit coding on Solaris

From: James Tucker (jftucker_at_gmail.com)
Date: 09/30/04

  • Next message: Jason Thibeault: "Re: [Full-Disclosure] Spyware? Worm? Trojan? "face license free bait""
    To: fabio <fabio@crearium.com>
    Date: Thu, 30 Sep 2004 01:36:56 +0100
    
    

    well, heres what gmail ads thought of your mail:

    Need Exploits?
    Immunity Canvas has over 100 for Solaris, Linux, and Win32
    www.immunitysec.com
    DSO Exploit Removal
    Download and try for free. aff. Stop Your Privacy Invasion.
    www.NoAdware.net
    DSO Exploit Remover
    Download and try for free. Block privacy invasion. aff
    www.SpywareNuker.com
    Related Pages
    JPEG Exploit Hits Usenet, Worm Close Behind
    TechWeb - Sep 28, 2004
    By TechWeb News. An exploit attacking the most recent Windows bug is ...
    QNX RTOS FTP Client "QUOTE" Command Format String Vulnerability
    Secunia - Sep 28, 2004
    Select a product and view a complete list of all Patched/Unpatched ...
    SecurityFocus HOME Infocus: Solaris 10 Security
    SecurityFocus is designed to facilitate discussion on security ...
    www.securityfocus.com
    Buffer Overflow Vulnerabilities In Four Unix Programs
    Buffer Overflow Vulnerabilities In Four Unix Programs: Sendmail, ...
    www.networkassociates.com

    How about that for starters. Heh, maybe advertising is useful
    afterall; certainly saved a few seconds.

    :p ;)

    On Tue, 28 Sep 2004 22:44:45 -0600, fabio <fabio@crearium.com> wrote:
    > Hi.
    >
    > I would like to know resources (web pages, documents, mailing lists)
    > about exploit coding on Solaris sparc. I want to understand security
    > bugs in Solaris sprac. the idea is know how the exploits work on this
    > architecture and the impact of security flaws from a developer point of
    > view. I want to know solaris internals and how malicious code works.
    >
    > All the documents avalible refers to linux and intel architecture. For
    > example, I want to do a university project about latest Xsun
    > vulnerability. I dont have documents and resources.
    >
    > Any link or comment is welcome.
    >
    > Thanks in advance.
    >
    > _______________________________________________
    > Full-Disclosure - We believe in it.
    > Charter: http://lists.netsys.com/full-disclosure-charter.html
    >

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Jason Thibeault: "Re: [Full-Disclosure] Spyware? Worm? Trojan? "face license free bait""

    Relevant Pages

    • [NEWS] Hardening Solaris for MGC
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... The Media Gateway Controller product is installed on top of Solaris ... In the default installation, Solaris has several known ... Since vulnerabilities are in the underlying Operating System customers do ...
      (Securiteam)
    • [UNIX] Remote Root Exploitation of Default Solaris sadmind Setting
      ... Get your security news from a reliable source. ... its Solaris operating system to help administrators manage systems ... The sadmind daemon is used by Solstice AdminSuite applications to ... documented to some extent in Sun documentation, ...
      (Securiteam)
    • [EXPL] Solaris Xlock Heap Overflow Vulnerability (Exploit, XUSERFILESEARCHPATH)
      ... Solaris Xlock Heap Overflow Vulnerability ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... * sol_x86_xlockex.c - Proof of Concept Code for xlock heap overflow bug. ...
      (Securiteam)
    • Cisco Security Advisory: Hardening of Solaris OS for MGC
      ... Solaris operating system. ... In order to guarantee the stability of the application Cisco must ... The second issue is the security of the default Solaris installation. ...
      (Bugtraq)
    • [UNIX] William LeFebvre "top" Format String Vulnerability
      ... Get your security news from a reliable source. ... Over four years later the vulnerability ... bug and the issue has since been patched. ... OpenBSD, FreeBSD, SCO Skunkware, and Solaris have all been subject to this ...
      (Securiteam)