Vulnerability Development mailing list archives

Re: Local root through vulnerability in ping on linux.


From: Michal Zalewski <lcamtuf () DIONE IDS PL>
Date: Tue, 22 Aug 2000 15:57:03 +0200

On Tue, 22 Aug 2000, Bluefish (P.Magnusson) wrote:

Doesn't seem exploitable, but a bit funny :)

To keep it short, no coredump so far, neither as root or user, no matter
packet size while doing /usr/sbin/traceroute -g 127.0.0.1 127.0.0.1

Try with other IPs that will expand to different DNS entries. Also, try
replacing one of these IPs with DNS name and so on.

Every time, effect will be different ;P

_______________________________________________________
Michal Zalewski [lcamtuf () tpi pl] [tp.internet/security]
[http://lcamtuf.na.export.pl] <=--=> bash$ :(){ :|:&};:
=-----=> God is real, unless declared integer. <=-----=


Current thread: