which freebsd/apache is exploitable at all?

From: Ingram (Vail@gmx.net)
Date: 08/21/02


Date: Wed, 21 Aug 2002 17:00:37 +0200 (MEST)
From: Ingram <Vail@gmx.net>
To: pen-test@securityfocus.com

greetings,

which Version of FreeBSD is really exploitable with the gobbles nosejob.c
exploit?
I tried it on several versions, but couldn´t manage to get shell. On OpenBSD
it´s
not a problem, i could even spawn a shell on 2.9 which is not "supported" by
nosejob/scalp.

I tried the following configs:

FreeBSD 4.4 RELEASE + Apache 1.3.22
FreeBSD 4.5 RELEASE + Apache 1.3.23
FreeBSD 4.5 RELEASE + Apache 1.3.24
FreeBSD 4.6 RELEASE + Apache 1.3.24
FreeBSD 4.6 RELEASE + Apache 1.3.25

I use the cygwin win32 port of the gobbles nosejob.

Could anybody point me to the right direction how to exploit the apache
chunked vuln
on FreeBSD and which version/parameters actually work?

thx in advantage
Ingram

-- 
GMX - Die Kommunikationsplattform im Internet.
http://www.gmx.net

---------------------------------------------------------------------------- This list is provided by the SecurityFocus Security Intelligence Alert (SIA) Service. For more information on SecurityFocus' SIA service which automatically alerts you to the latest security vulnerabilities please see: https://alerts.securityfocus.com/



Relevant Pages

  • Re: how to install samba and windows xp ?
    ... the question and the freebsd mails. ... >licence so I got rid of windows server and Installed ... >I installed the default package of apache, ... >and also i cant share my internet conection. ...
    (freebsd-newbies)
  • Re: mod_auth_kerb2 broken in 8-STABLE? Or is it heimdal to blame?
    ... After the installation ), the server refused to start giving the error: ... What is stated, is that heimdal-1.1 was broken in FreeBSD, and that it should be fixed at some moment in the future. ... ap22-mod_auth_kerb-5.4_3 An Apache module for authenticating users with Kerberos v5 ...
    (freebsd-stable)
  • Re: (Another) simple benchmark
    ... while this is the default on FreeBSD I would think ... the threaded worker would be used on a lot of linux dists, since they don't have the option to easily rebuild it. ... Debian have avoided threaded apache for a long time. ... threading is still under development and you shouldn't ...
    (freebsd-performance)
  • Re: (Another) simple benchmark
    ... In absence of anything smarter to do, I installed WBEL 3 Linux ... Apache is a well known server-grade product, ... It shouldn't behave this badly on FreeBSD. ... FreeBSD CPU time was 100% spent, with 90%-95% spent in sys time ...
    (freebsd-current)
  • Re: (Another) simple benchmark
    ... In absence of anything smarter to do, I installed WBEL 3 Linux ... Apache is a well known server-grade product, ... It shouldn't behave this badly on FreeBSD. ... FreeBSD CPU time was 100% spent, with 90%-95% spent in sys time ...
    (freebsd-performance)