OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: Apache 1.3

From: Yves Younan (yyounanfort-knox.org)
Date: Tue Sep 14 2004 - 16:29:42 CDT


On Tue, 2004-09-14 at 12:40, aleyconsolbyexpotel.com wrote:
> Anybody know of any code/tools to exploit the Apache chunking integer
> overflow with Apache 1.3.9 on digital Unix? I'm looking for a bit of
> assistance with a pen-test.
I don't know of any specific tools. But, if Digital Unix does not
implement it's memcpy in a similar way as BSD (i.e. it mimics the
behavior of memmove), this may not be possible.

- YY
They that give up essential liberty to obtain a little temporary safety
deserve neither liberty nor safety.
                - Benjamin Franklin

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)

iD8DBQBBR2LFrwaBAykIYdsRAsGGAJoDS7xnkQsw0wM4MpYWXZvgrEZ1TwCdH6MR
hMe0bPpejNhkO4CJsussiDc=
=kxHU
-----END PGP SIGNATURE-----