All of lore.kernel.org
 help / color / mirror / Atom feed
* Exploit for the Kernel
@ 2002-10-19  1:42 Breno
  2002-10-19  1:51 ` David S. Miller
  2002-10-19  6:39 ` Wolfgang Fritz
  0 siblings, 2 replies; 6+ messages in thread
From: Breno @ 2002-10-19  1:42 UTC (permalink / raw)
  To: Kernel List

http://online.securityfocus.com/archive/1/295855/2002-10-15/2002-10-21/1 



Breno


^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: Exploit for the Kernel
  2002-10-19  1:42 Exploit for the Kernel Breno
@ 2002-10-19  1:51 ` David S. Miller
  2002-10-19  2:07   ` Keith Owens
  2002-10-19  6:39 ` Wolfgang Fritz
  1 sibling, 1 reply; 6+ messages in thread
From: David S. Miller @ 2002-10-19  1:51 UTC (permalink / raw)
  To: breno_silva; +Cc: linux-kernel

   From: "Breno" <breno_silva@bandnet.com.br>
   Date: Fri, 18 Oct 2002 22:42:12 -0300

   http://online.securityfocus.com/archive/1/295855/2002-10-15/2002-10-21/1 
   
There is nothing concrete at all about said "exploit".

It looks like just a clever way to divert the victim's
attention from the real mechanism these guys are using
to root peoples boxes.

It is nearly impossible for a TCP frag handling exploit
to allow a root shell and socket to that shell to be
created.  So I think the claims are total nonsense.

^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: Exploit for the Kernel
  2002-10-19  2:07   ` Keith Owens
@ 2002-10-19  2:06     ` David S. Miller
  0 siblings, 0 replies; 6+ messages in thread
From: David S. Miller @ 2002-10-19  2:06 UTC (permalink / raw)
  To: kaos; +Cc: linux-kernel

   From: Keith Owens <kaos@ocs.com.au>
   Date: Sat, 19 Oct 2002 12:07:10 +1000
   
   The last mail on that thread is interesting[*], fooling the victim into
   running a vulnerable version of tcpdump by claiming a vulnerability in
   TCP.

Yes, I noted that as well.

Another tip off is that ABFrag 'works' on BSD too :-)

^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: Exploit for the Kernel
  2002-10-19  1:51 ` David S. Miller
@ 2002-10-19  2:07   ` Keith Owens
  2002-10-19  2:06     ` David S. Miller
  0 siblings, 1 reply; 6+ messages in thread
From: Keith Owens @ 2002-10-19  2:07 UTC (permalink / raw)
  To: linux-kernel

On Fri, 18 Oct 2002 18:51:16 -0700 (PDT), 
"David S. Miller" <davem@redhat.com> wrote:
>   From: "Breno" <breno_silva@bandnet.com.br>
>   Date: Fri, 18 Oct 2002 22:42:12 -0300
>
>   http://online.securityfocus.com/archive/1/295855/2002-10-15/2002-10-21/1 
>   
>There is nothing concrete at all about said "exploit".
>
>It looks like just a clever way to divert the victim's
>attention from the real mechanism these guys are using
>to root peoples boxes.

Agreed.

>It is nearly impossible for a TCP frag handling exploit
>to allow a root shell and socket to that shell to be
>created.  So I think the claims are total nonsense.

The last mail on that thread is interesting[*], fooling the victim into
running a vulnerable version of tcpdump by claiming a vulnerability in
TCP.

[*] http://online.securityfocus.com/archive/1/295855/2002-10-15/2002-10-21/2


^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: Exploit for the Kernel
  2002-10-19  1:42 Exploit for the Kernel Breno
  2002-10-19  1:51 ` David S. Miller
@ 2002-10-19  6:39 ` Wolfgang Fritz
  2002-10-19  8:48   ` Keith Owens
  1 sibling, 1 reply; 6+ messages in thread
From: Wolfgang Fritz @ 2002-10-19  6:39 UTC (permalink / raw)
  To: linux-kernel

Breno wrote:

> 
http://online.securityfocus.com/archive/1/295855/2002-10-15/2002-10-21/1
> 
> 
> 
> Breno
> 
See www.heise.de (in german):

http://www.heise.de/newsticker/data/pab-18.10.02-000/

Wolfgang

> -
> To unsubscribe from this list: send the line "unsubscribe
> linux-kernel" in the body of a message to majordomo@vger.kernel.org
> More majordomo info at  http://vger.kernel.org/majordomo-info.html
> Please read the FAQ at  http://www.tux.org/lkml/



^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: Exploit for the Kernel
  2002-10-19  6:39 ` Wolfgang Fritz
@ 2002-10-19  8:48   ` Keith Owens
  0 siblings, 0 replies; 6+ messages in thread
From: Keith Owens @ 2002-10-19  8:48 UTC (permalink / raw)
  To: linux-kernel

On Sat, 19 Oct 2002 08:39:34 +0200, 
Wolfgang Fritz <wolfgang.fritz@gmx.net> wrote:
>Breno wrote:
>>http://online.securityfocus.com/archive/1/295855/2002-10-15/2002-10-21/1
>See www.heise.de (in german):
>
>http://www.heise.de/newsticker/data/pab-18.10.02-000/

English: http://www.heise.de/english/newsticker/data/jk-18.10.02-006/

  A message posted on the Security Mailinglist BugTraq about an exploit
  for Linux kernels "ABFrags" has turned out to be a fake.

Let it die ...


^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2002-10-19  8:43 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2002-10-19  1:42 Exploit for the Kernel Breno
2002-10-19  1:51 ` David S. Miller
2002-10-19  2:07   ` Keith Owens
2002-10-19  2:06     ` David S. Miller
2002-10-19  6:39 ` Wolfgang Fritz
2002-10-19  8:48   ` Keith Owens

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.