Security Incidents mailing list archives

Re: Need two files for testing


From: "Shad Williams" <SWILLIAM () boisestate edu>
Date: Wed, 17 Dec 2003 14:53:36 -0700

michael - 

i just sent the file from our windows real server 8.0  system to your
email address. hope this helps!

shad

Michael Lastor <mlastor () hawaii rr com> 12/16/2003 2:46:09 PM >>>


I am working on a certification as an incident handler, and in order to
get the certification I need to submit a paper and take some tests.  The
paper needs to be about a specific exploit, show exactly how it works
(captured packets, logs, etc.) and how to clean up after the fact.  The
exploit that I would like to write about is the one for the Real
Networks Helix Server that was released around August 2003.  The "fix"
from Real Networks was to remove the vulnerable files from your system. 
These files are:
vsrcplin.so.9.0 for the *nix platforms and vsrc3260.dll for the windows
platform.
The latest versions that you can download from Real's website have the
fix already incorporated in them so they are no longer vulnerable to
this attack.  I am wondering, does anyone have these two files
(pre-August 2003) that I can get a copy of, so that I can see how this
exploit works and start working on my paper.  All I need is the files
themselves, not the exploit.
Thanks,
ML

---------------------------------------------------------------------------
----------------------------------------------------------------------------


---------------------------------------------------------------------------
----------------------------------------------------------------------------


Current thread: