Nmap Development mailing list archives
Re: [NSE] ftp-libopie.nse in response to CVE-2010-1938
From: Henri Salo <henri () nerv fi>
Date: Thu, 27 May 2010 21:06:56 +0300
On Thu, 27 May 2010 19:34:39 +0200 Gutek <ange.gutek () gmail com> wrote:
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 A vulnerability that has been published today affects the OPIE Authentication System (libopie). According to the researchers it could hit many systems like - - OpenSuSE - - wu-ftpd - - mod_opie - - PAM - - openssh (modified by FreeBSD/DragonflyBSD Team) - - sudo - - opiesu - - popper - - Probably much more... Original advisory : http://securityreason.com/achievement_securityalert/87 See also : http://security.freebsd.org/advisories/FreeBSD-SA-10:05.opie.asc Please find attached their PoC as a script for Nmap. Example Output : - -- PORT STATE SERVICE - -- 21/tcp open ftp - -- | ftp-libopie: Likely prone to CVE-2010-1938 (OPIE off-by-one stack overflow) - -- |_See http://security.freebsd.org/advisories/FreeBSD-SA-10:05.opie.asc A.G. -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.12 (GNU/Linux) Comment: Using GnuPG with SUSE - http://enigmail.mozdev.org/ iEYEARECAAYFAkv+rS8ACgkQ3aDTTO0ha7j4igCffydmk9Y+U6ocVSNI5RwopoGh vc0AniRSZZEkW5vgImS4czZsTTzS1bqf =No6K -----END PGP SIGNATURE-----
Great job! Best regards, Henri Salo _______________________________________________ Sent through the nmap-dev mailing list http://cgi.insecure.org/mailman/listinfo/nmap-dev Archived at http://seclists.org/nmap-dev/
Current thread:
- [NSE] ftp-libopie.nse in response to CVE-2010-1938 Gutek (May 27)
- Re: [NSE] ftp-libopie.nse in response to CVE-2010-1938 Henri Salo (May 27)
- Re: [NSE] ftp-libopie.nse in response to CVE-2010-1938 David Fifield (Jun 13)
- Re: [NSE] ftp-libopie.nse in response to CVE-2010-1938 Gutek (Jun 14)
- Re: [NSE] ftp-libopie.nse in response to CVE-2010-1938 David Fifield (Jun 21)
- Re: [NSE] ftp-libopie.nse in response to CVE-2010-1938 Gutek (Jun 14)