OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: BrightStor ARCserve Backup buffer overflow PoC

From: H D Moore (sflistdigitaloffense.net)
Date: Fri Feb 11 2005 - 17:49:22 CST


Is this for the same flaw detailed at the URL below? The iDefense bug
seems to be in the UDP service, but this affects the TCP service...

 http://www.idefense.com/application/poi/display?id=194&type=vulnerabilities

We just posted an exploit for the UDP overflow (thanks Syscall) to the
metasploit.com web site, it does not seem like the same vulnerability:

 http://metasploit.com/projects/Framework/exploits.html#cabrightstor_disco

-HD

On Friday 11 February 2005 12:19, cybertronicgmx.net wrote:
> //cybertronicgmx.net
>
> #define PORT 41523