Likes Likes:  0
Resultaten 1 tot 2 van de 2
Geen
  1. #1
    Shiva Persaud
    Re: /usr/bin/enq and /usr/bin/X11/aixterm exploit in AIX
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: /usr/bin/enq and /usr/bin/X11/aixterm exploit in AIX





    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    <1>
    The aixterm issue is addressed in an efix which can be downloaded from:

    ftp://ftp.software.ibm.com/aix/efixe...IM_efix.tar.Z.

    <2>
    The enq issue was fixed in Feb 2000. The following filesets contain the most
    current version of enq:

    For AIX 4.3.3:
    bos.rte.printers.4.3.3.78

    For AIX 5.1.0:
    bos.rte.printers.5.1.0.25

    For AIX 5.2.0:
    bos.rte.printers.5.2.0.0


    To request the PGP public key that can be used to encrypt new AIX
    security vulnerabilities, send email to security-alert@austin.ibm.com
    with a subject of "get key".


    Shiva Persaud
    AIX Security Developer
    shivapd@us.ibm.com
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.2.0 (AIX)

    iD8DBQE+UYPXcnMXzUg7txIRAkRNAJsFOHbxbkAc/pqqZFCCr3YK9vy5DACeMmN6
    ALLNjBcnTx+VfZIiuPCDzdQ=
    =ufwJ
    -----END PGP SIGNATURE-----




    Shiva Persaud
    AIX Security Developer
    Phone: 512-838-1192
    shivapd@us.ibm.com





    choi sungwoon
    <monocat2@hanmail To: bugtraq@securityfocus.com
    .net> cc:
    Subject: /usr/bin/enq and /usr/bin/X11/aixterm exploit in AIX
    02/17/2003 01:00
    AM
    Please respond to
    Shiva Persaud







    /*
    Title: /usr/bin/enq and /usr/bin/X11/aixterm exploit in AIX
    Vulnerability found by Esa Etelavoun, iDEFFENSE
    Author: green(green@wowhacker.org), dragory(dragory@wowhacker.org)
    Tested on AIX 4.3.3/RS6000
    Reference: lsd-pl.net's exploit

    Thanks to wowcode & overhead team at Wowhacker(http://www.wowhacker.org)
    */



    I tested BOF in AIX lately.
    These are exploits of /usr/bin/enq and /usr/bin/X11/aixterm in AIX.
    (My system language is Korean...)





  2. #2
    Keith Stevenson
    Re: /usr/bin/enq and /usr/bin/X11/aixterm exploit in AIX
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: /usr/bin/enq and /usr/bin/X11/aixterm exploit in AIX

    On Mon, Feb 17, 2003 at 07:00:23AM -0000, choi sungwoon wrote:
    >
    > 1. /usr/bin/enq
    > /*
    > http://online.securityfocus.com/bid/2034


    This one is quite old. As referenced in the above URL, enq is fixed by APAR
    IY08143. The vulnerability was resolved in filesets:

    bos.rte.printers:4.3.3.1
    printers.rte:4.3.3.11

    >
    > 2. /usr/bin/X11/aixterm
    > /*
    > [dragory@aix dragory]$ cp /usr/bin/X11/aixterm ./test
    > [dragory@aix dragory]$ ./test -display x.x.x.x:0 -im `perl -
    > e 'print "x"x400'`
    > Segmentation fault (core dumped)


    You appear to be overflowing the input method identifier here. I don't see
    anything explicitly mentioning this vulnerability in IBM's patch database. I
    would be very interested in seeing the output of 'oslevel -r' and
    'lslpp -al X11.apps.aixterm' on your test system.

    Regards,
    --Keith Stevenson--

    --
    Keith Stevenson
    System Programmer - Data Center Services - University of Louisville
    keith.stevenson@louisville.edu
    GPG key fingerprint = 332D 97F0 6321 F00F 8EE7 2D44 00D8 F384 75BB 89AE

Webhostingtalk.nl

Contact

  • Rokin 113-115
  • 1012 KP, Amsterdam
  • Nederland
  • Contact
© Copyright 2001-2026 Webhostingtalk.nl.
Web Statistics