Re: [Full-disclosure] FreeBSD ftpd and ProFTPd on FreeBSD remote r00t exploit

2011-12-01 Thread Jason Hellenthal


On Wed, Nov 30, 2011 at 11:05:08PM +0100, HI-TECH . wrote:
 Hi lists,
 sorry if I offended anyone with by referring to teso,
 I really like teso as you might also.
 all this happend because I was drunk hehe :
 I hope you enjoy this release!
 
 Am 30. November 2011 20:32 schrieb HI-TECH .
 isowarez.isowarez.isowa...@googlemail.com:
  /* KCOPE2011 - x86/amd64 bsd ftpd remote root exploit
  ?*
  ?* KINGCOPE CONFIDENTIAL - SOURCE MATERIALS
  ?*
  ?* This is unpublished proprietary source code of KINGCOPE Security.
  ?*
  ?* (C) COPYRIGHT KINGCOPE Security, 2011
  ?* All Rights Reserved
  ?*
  ?*
  ?* bug found by Kingcope
  ?* thanks to noone except alex whose damn down
  ?*
  ?* tested against: ?FreeBSD-8.2,8.1,7.2,7.1 i386;
  ?* ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ?FreeBSD-6.3 i386
  ?* ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ?FreeBSD-5.5,5.2 i386
  ?* ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ?FreeBSD-8.2 amd64
  ?* ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ?FreeBSD-7.3, 7.0 amd64
  ?* ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ?FreeBSD-6.4, 6.2 amd64
  ?*
  ?*/
 
  I m better than TESO 7350 see attached.
  I aint mad at cha
  and dont forget that the scene is fucked.
  and that the public scene is fucked too, kind of.
  youse a down ass bitch and I aint mad at cha.
  thanks lsd you are the only one NORMAL.
  hear the track before you see the code:
  http://www.youtube.com/watch?v=krxu9_dRUwQ
  BTW my box (isowarez.de) got hacked so expect me in a zine :
 
  /Signed the awesome Kingcope
 
 

Fun stuff... Thanks

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] FreeBSD ftpd and ProFTPd on FreeBSD remote r00t exploit

2011-12-01 Thread Michal Zalewski
 If you want to respect the license of this code you cannot include the
 exploit in your software.

And don't get me started about my patent on NOP sleds!

/mz

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] FreeBSD ftpd and ProFTPd on FreeBSD remote r00t exploit

2011-11-30 Thread noreply
Hello there!
The exploit roaringbeast will be added to Exploit pack

Authors name and code/license will be respected and it will be ported 
to Python with minimal modifications

The code will be uploaded to Exploit Pack Git Repo and will be 
available to all our users

Thank you and congratulations for such a great job!

JSacco

On 30.11.2011 13:32, HI-TECH . wrote:
 /* KCOPE2011 - x86/amd64 bsd ftpd remote root exploit
  *
  * KINGCOPE CONFIDENTIAL - SOURCE MATERIALS
  *
  * This is unpublished proprietary source code of KINGCOPE Security.
  *
  * (C) COPYRIGHT KINGCOPE Security, 2011
  * All Rights Reserved
  *

 
 *
  * bug found by Kingcope
  * thanks to noone except alex whose damn down
  *
  * tested against:  FreeBSD-8.2,8.1,7.2,7.1 i386;
  *FreeBSD-6.3 i386
  *FreeBSD-5.5,5.2 i386
  *FreeBSD-8.2 amd64
  *FreeBSD-7.3, 7.0 amd64
  *FreeBSD-6.4, 6.2 amd64
  *
  */

 I m better than TESO 7350 see attached.
 I aint mad at cha
 and dont forget that the scene is fucked.
 and that the public scene is fucked too, kind of.
 youse a down ass bitch and I aint mad at cha.
 thanks lsd you are the only one NORMAL.
 hear the track before you see the code:
 http://www.youtube.com/watch?v=krxu9_dRUwQ
 BTW my box (isowarez.de) got hacked so expect me in a zine :

 /Signed the awesome Kingcope

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] FreeBSD ftpd and ProFTPd on FreeBSD remote r00t exploit

2011-11-30 Thread HI-TECH .
Hi lists,
sorry if I offended anyone with by referring to teso,
I really like teso as you might also.
all this happend because I was drunk hehe :
I hope you enjoy this release!

Am 30. November 2011 20:32 schrieb HI-TECH .
isowarez.isowarez.isowa...@googlemail.com:
 /* KCOPE2011 - x86/amd64 bsd ftpd remote root exploit
  *
  * KINGCOPE CONFIDENTIAL - SOURCE MATERIALS
  *
  * This is unpublished proprietary source code of KINGCOPE Security.
  *
  * (C) COPYRIGHT KINGCOPE Security, 2011
  * All Rights Reserved
  *
  *
  * bug found by Kingcope
  * thanks to noone except alex whose damn down
  *
  * tested against:  FreeBSD-8.2,8.1,7.2,7.1 i386;
  *                                      FreeBSD-6.3 i386
  *                                      FreeBSD-5.5,5.2 i386
  *                                      FreeBSD-8.2 amd64
  *                                      FreeBSD-7.3, 7.0 amd64
  *                                      FreeBSD-6.4, 6.2 amd64
  *
  */

 I m better than TESO 7350 see attached.
 I aint mad at cha
 and dont forget that the scene is fucked.
 and that the public scene is fucked too, kind of.
 youse a down ass bitch and I aint mad at cha.
 thanks lsd you are the only one NORMAL.
 hear the track before you see the code:
 http://www.youtube.com/watch?v=krxu9_dRUwQ
 BTW my box (isowarez.de) got hacked so expect me in a zine :

 /Signed the awesome Kingcope


___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] FreeBSD ftpd and ProFTPd on FreeBSD remote r00t exploit

2011-11-30 Thread root
If you want to respect the license of this code you cannot include the
exploit in your software.

All rights reserved means you cannot include it in other products,
actually nobody can except the author.

You should ask the author for permission to redistribute the exploit or
re-implement it.



On 11/30/2011 06:11 PM, nore...@exploitpack.com wrote:
 Hello there!
 The exploit roaringbeast will be added to Exploit pack
 
 Authors name and code/license will be respected and it will be ported 
 to Python with minimal modifications
 
 The code will be uploaded to Exploit Pack Git Repo and will be 
 available to all our users
 
 Thank you and congratulations for such a great job!
 
 JSacco
 
 On 30.11.2011 13:32, HI-TECH . wrote:
 /* KCOPE2011 - x86/amd64 bsd ftpd remote root exploit
  *
  * KINGCOPE CONFIDENTIAL - SOURCE MATERIALS
  *
  * This is unpublished proprietary source code of KINGCOPE Security.
  *
  * (C) COPYRIGHT KINGCOPE Security, 2011
  * All Rights Reserved
  *


 *
  * bug found by Kingcope
  * thanks to noone except alex whose damn down
  *
  * tested against:  FreeBSD-8.2,8.1,7.2,7.1 i386;
  *   FreeBSD-6.3 i386
  *   FreeBSD-5.5,5.2 i386
  *   FreeBSD-8.2 amd64
  *   FreeBSD-7.3, 7.0 amd64
  *   FreeBSD-6.4, 6.2 amd64
  *
  */

 I m better than TESO 7350 see attached.
 I aint mad at cha
 and dont forget that the scene is fucked.
 and that the public scene is fucked too, kind of.
 youse a down ass bitch and I aint mad at cha.
 thanks lsd you are the only one NORMAL.
 hear the track before you see the code:
 http://www.youtube.com/watch?v=krxu9_dRUwQ
 BTW my box (isowarez.de) got hacked so expect me in a zine :

 /Signed the awesome Kingcope
 
 ___
 Full-Disclosure - We believe in it.
 Charter: http://lists.grok.org.uk/full-disclosure-charter.html
 Hosted and sponsored by Secunia - http://secunia.com/
 

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/