OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: KOJIMA Hajime (kjmrins.ryukoku.ac.jp)
Date: Fri Feb 08 2002 - 02:16:51 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    In <017801c1b065$ba68f270$0b01a8c0tomh61ib59mm58>,
    "Global InterSec Research" wrote:
    |
    | As with many of the vulnerabilities in DeleGate, a SIGSEGV occurs
    | when attempting to strcpy() unexpectedly long strings.
    | In spite of attempts DeleGate makes to randomise the stack, we
    | were successful in overwriting the Extended instruction pointer.
    | Although the stack randomisation functions make things harder, they
    | do not make arbitrary command execution impossible.

      And, delegate has execve(2) trap (-Tx). Can you break it?

    - kjm