OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: nicolas brulez (brulezcartel-securite.fr)
Date: Wed Feb 20 2002 - 11:24:39 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    Hello,

    I have seen 2 advisories for avirt 4.2 gateway.
    Did they patch it without modifying the version ?
    I tried the proof of concept exploit and it did nothing but close the
    server.
    I wanted to trigger the buffer overflow on the web server too, in order
    to write a proof of concept exploit
    but my attempts did nothhing but close the server again.. (something
    like 4000 chars)
    I never managed to overwrite my EIP.(or doesn't it crash when you do it ? )
    I was wondering if they patched it in a dodgy way ?
    Sorry if it is not the good place for such a post ;-)

    Best Regards,

    Nicolas Brulez
    Cartel-Securite.