OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: exploit code targeting OpenSSL and Mod_SSL ?

From: Geoffroy Raimbault (graimbaultlynx-technologies.com)
Date: Tue Apr 15 2003 - 11:19:16 CDT


Take a look at this page :

http://lists.netsys.com/pipermail/full-disclosure/2002-September/001913.html

It's an exploit for the KEY_ARG heap overflow in mod_ssl under Apache
written by Solar Eclipse.

It is provided with a good documentation on how to exploit the
vulnerability.

Regards,

Geoffroy Raimbault
Information Security Consultant
http://www.lynx-technologies.com

----- Original Message -----
From: "John" <johnccostayahoo.ca>
To: <vuln-devsecurityfocus.com>
Sent: Tuesday, April 15, 2003 4:18 AM
Subject: exploit code targeting OpenSSL and Mod_SSL ?

>
>
> Is anyone aware of the existence of exploit code in the
> wild that is currently targeting OpenSSL and Mod_SSL
> vulnerabilities?
>
> Tx
> John
>