* Exploit for the Kernel
@ 2002-10-19 1:42 Breno
2002-10-19 1:51 ` David S. Miller
2002-10-19 6:39 ` Wolfgang Fritz
0 siblings, 2 replies; 6+ messages in thread
From: Breno @ 2002-10-19 1:42 UTC (permalink / raw)
To: Kernel List
http://online.securityfocus.com/archive/1/295855/2002-10-15/2002-10-21/1
Breno
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: Exploit for the Kernel
2002-10-19 1:42 Exploit for the Kernel Breno
@ 2002-10-19 1:51 ` David S. Miller
2002-10-19 2:07 ` Keith Owens
2002-10-19 6:39 ` Wolfgang Fritz
1 sibling, 1 reply; 6+ messages in thread
From: David S. Miller @ 2002-10-19 1:51 UTC (permalink / raw)
To: breno_silva; +Cc: linux-kernel
From: "Breno" <breno_silva@bandnet.com.br>
Date: Fri, 18 Oct 2002 22:42:12 -0300
http://online.securityfocus.com/archive/1/295855/2002-10-15/2002-10-21/1
There is nothing concrete at all about said "exploit".
It looks like just a clever way to divert the victim's
attention from the real mechanism these guys are using
to root peoples boxes.
It is nearly impossible for a TCP frag handling exploit
to allow a root shell and socket to that shell to be
created. So I think the claims are total nonsense.
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: Exploit for the Kernel
2002-10-19 2:07 ` Keith Owens
@ 2002-10-19 2:06 ` David S. Miller
0 siblings, 0 replies; 6+ messages in thread
From: David S. Miller @ 2002-10-19 2:06 UTC (permalink / raw)
To: kaos; +Cc: linux-kernel
From: Keith Owens <kaos@ocs.com.au>
Date: Sat, 19 Oct 2002 12:07:10 +1000
The last mail on that thread is interesting[*], fooling the victim into
running a vulnerable version of tcpdump by claiming a vulnerability in
TCP.
Yes, I noted that as well.
Another tip off is that ABFrag 'works' on BSD too :-)
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: Exploit for the Kernel
2002-10-19 1:51 ` David S. Miller
@ 2002-10-19 2:07 ` Keith Owens
2002-10-19 2:06 ` David S. Miller
0 siblings, 1 reply; 6+ messages in thread
From: Keith Owens @ 2002-10-19 2:07 UTC (permalink / raw)
To: linux-kernel
On Fri, 18 Oct 2002 18:51:16 -0700 (PDT),
"David S. Miller" <davem@redhat.com> wrote:
> From: "Breno" <breno_silva@bandnet.com.br>
> Date: Fri, 18 Oct 2002 22:42:12 -0300
>
> http://online.securityfocus.com/archive/1/295855/2002-10-15/2002-10-21/1
>
>There is nothing concrete at all about said "exploit".
>
>It looks like just a clever way to divert the victim's
>attention from the real mechanism these guys are using
>to root peoples boxes.
Agreed.
>It is nearly impossible for a TCP frag handling exploit
>to allow a root shell and socket to that shell to be
>created. So I think the claims are total nonsense.
The last mail on that thread is interesting[*], fooling the victim into
running a vulnerable version of tcpdump by claiming a vulnerability in
TCP.
[*] http://online.securityfocus.com/archive/1/295855/2002-10-15/2002-10-21/2
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: Exploit for the Kernel
2002-10-19 1:42 Exploit for the Kernel Breno
2002-10-19 1:51 ` David S. Miller
@ 2002-10-19 6:39 ` Wolfgang Fritz
2002-10-19 8:48 ` Keith Owens
1 sibling, 1 reply; 6+ messages in thread
From: Wolfgang Fritz @ 2002-10-19 6:39 UTC (permalink / raw)
To: linux-kernel
Breno wrote:
>
http://online.securityfocus.com/archive/1/295855/2002-10-15/2002-10-21/1
>
>
>
> Breno
>
See www.heise.de (in german):
http://www.heise.de/newsticker/data/pab-18.10.02-000/
Wolfgang
> -
> To unsubscribe from this list: send the line "unsubscribe
> linux-kernel" in the body of a message to majordomo@vger.kernel.org
> More majordomo info at http://vger.kernel.org/majordomo-info.html
> Please read the FAQ at http://www.tux.org/lkml/
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: Exploit for the Kernel
2002-10-19 6:39 ` Wolfgang Fritz
@ 2002-10-19 8:48 ` Keith Owens
0 siblings, 0 replies; 6+ messages in thread
From: Keith Owens @ 2002-10-19 8:48 UTC (permalink / raw)
To: linux-kernel
On Sat, 19 Oct 2002 08:39:34 +0200,
Wolfgang Fritz <wolfgang.fritz@gmx.net> wrote:
>Breno wrote:
>>http://online.securityfocus.com/archive/1/295855/2002-10-15/2002-10-21/1
>See www.heise.de (in german):
>
>http://www.heise.de/newsticker/data/pab-18.10.02-000/
English: http://www.heise.de/english/newsticker/data/jk-18.10.02-006/
A message posted on the Security Mailinglist BugTraq about an exploit
for Linux kernels "ABFrags" has turned out to be a fake.
Let it die ...
^ permalink raw reply [flat|nested] 6+ messages in thread
end of thread, other threads:[~2002-10-19 8:43 UTC | newest]
Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2002-10-19 1:42 Exploit for the Kernel Breno
2002-10-19 1:51 ` David S. Miller
2002-10-19 2:07 ` Keith Owens
2002-10-19 2:06 ` David S. Miller
2002-10-19 6:39 ` Wolfgang Fritz
2002-10-19 8:48 ` Keith Owens
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.