Vulnerability Development mailing list archives

Re: telnet overflow


From: "J. Mallett" <jmallett () NewGold NET>
Date: Sun, 17 Feb 2002 17:10:22 +0000

On Sun, Feb 17, 2002 at 12:01:11PM -0500, Larry W. Cashdollar wrote:

Are you sure you didn't just crash the client?  Which binary did gdb say
the core file came from? telnet or telnetd?

He wouldn't have seen the 'Segmentation fault' message over the telnet
connection if telnetd had died...  Best case, on some systems, he may
have seen a 'Program telnetd (pid xxx) exited with signal 11' or some
such via syslog to all tty's root is logged in to, if he's root.  So
in other words, he crashed telnet(1).


Current thread: