OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Przemyslaw Frasunek (venglinFREEBSD.LUBLIN.PL)
Date: Sat Apr 07 2001 - 02:26:43 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    On Thu, Apr 05, 2001 at 10:56:45PM -0500, Stephen Clouse wrote:
    > Having no effect on ntp-4.0.99k compiled from official source on Slackware
    > 7.0. Exploit says /tmp/sh was spawned but it never actually runs (/bin/bash
    > mode didn't change).

    As I said, exploiting this overflow isn't so easy -- offset and align
    values vary from platform to platform. Exploit was tested only
    on bare RedHat 7.0 and FreeBSD 4.2-STABLE compiled with -O6 -fomit-frame-pointer
    -march=pentiumpro.

    Did your ntpd segfaulted after running an exploit?

    --
    * Fido: 2:480/124 ** WWW: http://www.frasunek.com/ ** NIC-HDL: PMF9-RIPE *
    * Inet: przemyslawfrasunek.com ** PGP: D48684904685DF43EA93AFA13BE170BF *