Dailydave mailing list archives

Re: Re: bleeding nessus/anything else


From: Dave Aitel <dave () immunitysec com>
Date: Thu, 05 May 2005 11:29:08 -0400

Steve Lord wrote:

Tom Ferris (and another bunch of people) wrote:
<snip>

As for the Indy.tv thing - anyone else look at it? I'm about to go to bed, but if I catch 5 minutes tomorrow I'll have a quick look. Are we checking for any particular curl vuln?

Well, a quick google and strings would say that perhaps the NTLM/kerberos bug is there? My scenario is that you could submit a valid mp3 to the engine for use, and then when people come to download it (via an embedded libcurl) you do whatever it is you need to do. I only spent a few minutes on it though. There's also a xml protocol for the Indy to server discussions which looks neat.

-dave


_______________________________________________
Dailydave mailing list
Dailydave () lists immunitysec com
https://lists.immunitysec.com/mailman/listinfo/dailydave


_______________________________________________
Dailydave mailing list
Dailydave () lists immunitysec com
https://lists.immunitysec.com/mailman/listinfo/dailydave


Current thread: