[Full-disclosure] BakBone Netvault 6.x/7.x Local Stack Buffer Overflow

class101_at_HAT-SQUAD.com
Date: 04/01/05

  • Next message: Humberto Duodenum Moore: "[Full-disclosure] Metasploit Framework v3.0 Alpha"
    To: "Full-Disclosure" <Full-Disclosure@lists.grok.org.uk>, <vulnwatch@vulnwatch.org>
    Date: Fri, 1 Apr 2005 16:51:53 +0200
    
    

    According to their website (bakbone.com),
    BakBone Netvault 6.x/7.x is a professional backup software with several
    offices in the world and some pro customers as Apple, AT&T, Pirelli, LMU,
    HP, NIP,NASA, etc....

    A Vulnerability exists in the configure.cfg file

    advisory: class101.org/netv-locsbof.pdf
    poc: class101.org/36/55/op.php

    recommendation: to set stricts acl rules on this file.
    -------------------------------------------------------------
    class101
    Jr. Researcher
    Hat-Squad.com
    -------------------------------------------------------------

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.grok.org.uk/full-disclosure-charter.html
    Hosted and sponsored by Secunia - http://secunia.com/


  • Next message: Humberto Duodenum Moore: "[Full-disclosure] Metasploit Framework v3.0 Alpha"

    Relevant Pages