Vulnerability Development mailing list archives

Re: Kill the DOG and win 100 000 DM


From: Lincoln Yeoh <lyeoh () POP JARING MY>
Date: Sat, 4 Nov 2000 23:25:39 +0800

4 days to get into an unfamiliar B style system? Hehe.

OK, some are familiar with it - but familiar enough to know of kernel bugs
and other undocumented features?

Anyway I think the script kiddies will just get in the way and slow things
down with DOS attacks, or just use up bandwidth and cpu.

There was a B style system where you could telnet in and su to root, and
you weren't supposed to be able to, since you were network level. A patch
fixed that, but it made me wonder if this B thingy is all it's claimed to
be given enough time to look at stuff and find the bugs.. Still security by
obscurity does work in the real world.

A more interesting test would be if there was a dynamic website with a
database backend. Such configs are common at most of the interesting sites
(to me anyway :) ).

Have fun!
Link.

At 05:18 PM 11/2/00 +0100, Pluym Christian wrote:
Hi,

there will be an interesting contest 6.-10. November, first one who modifies
the web page gets 100 000 German Marks (around $45 000). The system will be
running Pitbull 3 under Solaris 7, with http, telnet and smtp open.
Nov 7th /etc/passwd will be published
Nov 8th an user account will be given away
Nov 9th the root password will be published


Current thread: