Full Disclosure mailing list archives
Re: Insect Pro - Advisory 2011 0428 - Zero Day - Heap Buffer Overflow in xMatters APClient
From: Mario Vilas <mvilas () gmail com>
Date: Fri, 29 Apr 2011 00:43:58 -0300
Precisely. The poc triggers the bug by passing a very long command line argument, so it's assumed the attacker already has executed code. The only way this is exploitable is if the binary has suid (then the attacker can elevate privileges) or the command can be executed remotely (and the attacker additionaly cannot execute any other commands, but can mysteriously control the arguments). Unless either scenario is researched (and nothing in the advisory tells me so) I call bullshit. On Thu, Apr 28, 2011 at 6:09 PM, <Valdis.Kletnieks () vt edu> wrote:
On Thu, 28 Apr 2011 14:40:22 -0300, Mario Vilas said:Is the suid bit set on that binary? Otherwise, unless I'm missingsomethingit doesn't seem to be exploitable by an attacker...Who cares? You got code executed on the remote box, that's the *hard* part. Use that to inject a callback shell or something, use *that* to get yourself a shell prompt. At that point, download something else that exploits you to root - if you even *need* to, as quite often the Good Stuff is readable by non-root users.
-- “There's a reason we separate military and the police: one fights the enemy of the state, the other serves and protects the people. When the military becomes both, then the enemies of the state tend to become the people.”
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- Insect Pro - Advisory 2011 0428 - Zero Day - Heap Buffer Overflow in xMatters APClient Juan Sacco (Apr 28)
- Re: Insect Pro - Advisory 2011 0428 - Zero Day - Heap Buffer Overflow in xMatters APClient Mario Vilas (Apr 28)
- Re: Insect Pro - Advisory 2011 0428 - Zero Day - Heap Buffer Overflow in xMatters APClient Valdis . Kletnieks (Apr 28)
- Re: Insect Pro - Advisory 2011 0428 - Zero Day - Heap Buffer Overflow in xMatters APClient ichib0d crane (Apr 28)
- Re: Insect Pro - Advisory 2011 0428 - Zero Day - Heap Buffer Overflow in xMatters APClient ghost (Apr 28)
- Re: Insect Pro - Advisory 2011 0428 - Zero Day - Heap Buffer Overflow in xMatters APClient ichib0d crane (Apr 28)
- Re: Insect Pro - Advisory 2011 0428 - Zero Day - Heap Buffer Overflow in xMatters APClient -= Glowing Doom =- (Apr 29)
- Re: Insect Pro - Advisory 2011 0428 - Zero Day - Heap Buffer Overflow in xMatters APClient Cal Leeming (Apr 29)
- Re: Insect Pro - Advisory 2011 0428 - Zero Day - Heap Buffer Overflow in xMatters APClient Valdis . Kletnieks (Apr 28)
- Re: Insect Pro - Advisory 2011 0428 - Zero Day - Heap Buffer Overflow in xMatters APClient Mario Vilas (Apr 28)
- Re: Insect Pro - Advisory 2011 0428 - Zero Day - Heap Buffer Overflow in xMatters APClient Mario Vilas (Apr 28)
- Re: Insect Pro - Advisory 2011 0428 - Zero Day - Heap Buffer Overflow in xMatters APClient -= Glowing Doom =- (Apr 29)
- Re: Insect Pro - Advisory 2011 0428 - Zero Day - Heap Buffer Overflow in xMatters APClient R0me0 *** (Apr 29)