Security Incidents mailing list archives

Re: Linux Kernel Exploits / ABFrag


From: Benjamin Krueger <benjamin () seattleFenix net>
Date: Fri, 18 Oct 2002 17:25:35 -0700

* Ali Saifullah Khan (whipaz () attitudex com) [021018 16:22]:
I smell Burneye !! ..... what do you guys think ?

Ali Saifullah Khan,

I smell a fish story myself, but we'll see when we get that
binary. Btw Daniel, still waiting for a resend of that. =)

--- dr john halewood <john () frumious unidec co uk> wrote:
On Thursday 17 October 2002 2:00 am, daniel.roberts () hushmail com wrote:
Greetings.

ABfrag - Linux Kernel ( <= 2.4.20pre20 ) Remote Syncing exploit


I think this is a bit of a giveaway: mentioning a kernel that doesn't exist 
suggests this program is not what it claims to be (Marcelo released 
2.4.20-pre11 two days ago).

Someone more prone to conspiracy theorization might say that the author(s)
were planning a release before said kernel. Or perhaps writing a fix for the
bug and submitting it for 2.4.20pre20 to become heros. =P

cheers
john

-- 
Benjamin Krueger
----------------------------------------------------------------
Send mail w/ subject 'send public key' or query for (0x251A4B18)
Fingerprint = A642 F299 C1C1 C828 F186  A851 CFF0 7711 251A 4B18

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management 
and tracking system please see: http://aris.securityfocus.com


Current thread: