Dailydave mailing list archives

Finding 0days in Tokyo


From: Dave Aitel <dave () immunityinc com>
Date: Tue, 23 Oct 2007 13:45:42 -0400

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

For those of you going to PacSec, both Nico and Kostya will be there
talking and teaching a short class on binary analysis (aka, finding
0days with Immunity Debugger). This will be a good introduction to the
class they're teaching in Tokyo after that, if you're in that one as well.

Sometimes the hardest 0days to find are the simplest ones, as in the
below posting on milw0rm. (Is that the real password?)

http://www.milw0rm.com/exploits/4556

###########
#
<?php                                                                                     
 
 
#
#                                                                                           
 
 
#
# // This is probably
useless?                                                                  
#
# define('DB_NAME', 'wpmu');     // The name of the
database                                     #
# define('DB_USER', 'wpmu');     // Your MySQL
username                                          #
# define('DB_PASSWORD', 'JTO5T**CENSOR-HERE**'); // ...and
password                              #
# define('DB_HOST', 'two.wordpress.com');     // 99% chance you won't
need to change this value  #
#                                                                                           
 
 
#
#
require('define.php');                                                                    
 
 
#        
#                                                                                           
 
 
#
# require(ABSPATH .
'wpmu-settings.php');                                                     
 
#
#                                                                                           
 
 
#
# ?>           
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFHHjNFB8JNm+PA+iURAjNJAKCuDSqWHrnZFE28kbPlEtpVzEnxegCg4NqA
lYeyvjKvczoYId2gkgS08qE=
=hS+z
-----END PGP SIGNATURE-----

_______________________________________________
Dailydave mailing list
Dailydave () lists immunitysec com
http://lists.immunitysec.com/mailman/listinfo/dailydave


Current thread: