Re: [Full-disclosure] FreeBSD ftpd and ProFTPd on FreeBSD remote r00t exploit

2011-12-01 Thread Michal Zalewski
> If you want to respect the license of this code you cannot include the
> exploit in your software.

And don't get me started about my patent on NOP sleds!

/mz

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] FreeBSD ftpd and ProFTPd on FreeBSD remote r00t exploit

2011-12-01 Thread Jason Hellenthal


On Wed, Nov 30, 2011 at 11:05:08PM +0100, HI-TECH . wrote:
> Hi lists,
> sorry if I offended anyone with by referring to teso,
> I really like teso as you might also.
> all this happend because I was drunk hehe :>
> I hope you enjoy this release!
> 
> Am 30. November 2011 20:32 schrieb HI-TECH .
> :
> > /* KCOPE2011 - x86/amd64 bsd ftpd remote root exploit
> > ?*
> > ?* KINGCOPE CONFIDENTIAL - SOURCE MATERIALS
> > ?*
> > ?* This is unpublished proprietary source code of KINGCOPE Security.
> > ?*
> > ?* (C) COPYRIGHT KINGCOPE Security, 2011
> > ?* All Rights Reserved
> > ?*
> > ?*
> > ?* bug found by Kingcope
> > ?* thanks to noone except alex whose damn down
> > ?*
> > ?* tested against: ?FreeBSD-8.2,8.1,7.2,7.1 i386;
> > ?* ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ?FreeBSD-6.3 i386
> > ?* ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ?FreeBSD-5.5,5.2 i386
> > ?* ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ?FreeBSD-8.2 amd64
> > ?* ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ?FreeBSD-7.3, 7.0 amd64
> > ?* ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ?FreeBSD-6.4, 6.2 amd64
> > ?*
> > ?*/
> >
> > I m better than TESO 7350 see attached.
> > I aint mad at cha
> > and dont forget that the scene is fucked.
> > and that the public scene is fucked too, kind of.
> > youse a down ass bitch and I aint mad at cha.
> > thanks lsd you are the only one NORMAL.
> > hear the track before you see the code:
> > http://www.youtube.com/watch?v=krxu9_dRUwQ
> > BTW my box (isowarez.de) got hacked so expect me in a zine :>
> >
> > /Signed "the awesome" Kingcope
> >
> 

Fun stuff... Thanks

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] FreeBSD ftpd and ProFTPd on FreeBSD remote r00t exploit

2011-11-30 Thread root
If you want to respect the license of this code you cannot include the
exploit in your software.

"All rights reserved" means you cannot include it in other products,
actually nobody can except the author.

You should ask the author for permission to redistribute the exploit or
re-implement it.



On 11/30/2011 06:11 PM, nore...@exploitpack.com wrote:
> Hello there!
> The exploit "roaringbeast" will be added to Exploit pack
> 
> Authors name and code/license will be respected and it will be ported 
> to Python with minimal modifications
> 
> The code will be uploaded to Exploit Pack Git Repo and will be 
> available to all our users
> 
> Thank you and congratulations for such a great job!
> 
> JSacco
> 
> On 30.11.2011 13:32, HI-TECH . wrote:
>> /* KCOPE2011 - x86/amd64 bsd ftpd remote root exploit
>>  *
>>  * KINGCOPE CONFIDENTIAL - SOURCE MATERIALS
>>  *
>>  * This is unpublished proprietary source code of KINGCOPE Security.
>>  *
>>  * (C) COPYRIGHT KINGCOPE Security, 2011
>>  * All Rights Reserved
>>  *
>>
>>
>> *
>>  * bug found by Kingcope
>>  * thanks to noone except alex whose damn down
>>  *
>>  * tested against:  FreeBSD-8.2,8.1,7.2,7.1 i386;
>>  *   FreeBSD-6.3 i386
>>  *   FreeBSD-5.5,5.2 i386
>>  *   FreeBSD-8.2 amd64
>>  *   FreeBSD-7.3, 7.0 amd64
>>  *   FreeBSD-6.4, 6.2 amd64
>>  *
>>  */
>>
>> I m better than TESO 7350 see attached.
>> I aint mad at cha
>> and dont forget that the scene is fucked.
>> and that the public scene is fucked too, kind of.
>> youse a down ass bitch and I aint mad at cha.
>> thanks lsd you are the only one NORMAL.
>> hear the track before you see the code:
>> http://www.youtube.com/watch?v=krxu9_dRUwQ
>> BTW my box (isowarez.de) got hacked so expect me in a zine :>
>>
>> /Signed "the awesome" Kingcope
> 
> ___
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
> 

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] FreeBSD ftpd and ProFTPd on FreeBSD remote r00t exploit

2011-11-30 Thread HI-TECH .
Hi lists,
sorry if I offended anyone with by referring to teso,
I really like teso as you might also.
all this happend because I was drunk hehe :>
I hope you enjoy this release!

Am 30. November 2011 20:32 schrieb HI-TECH .
:
> /* KCOPE2011 - x86/amd64 bsd ftpd remote root exploit
>  *
>  * KINGCOPE CONFIDENTIAL - SOURCE MATERIALS
>  *
>  * This is unpublished proprietary source code of KINGCOPE Security.
>  *
>  * (C) COPYRIGHT KINGCOPE Security, 2011
>  * All Rights Reserved
>  *
>  *
>  * bug found by Kingcope
>  * thanks to noone except alex whose damn down
>  *
>  * tested against:  FreeBSD-8.2,8.1,7.2,7.1 i386;
>  *                                      FreeBSD-6.3 i386
>  *                                      FreeBSD-5.5,5.2 i386
>  *                                      FreeBSD-8.2 amd64
>  *                                      FreeBSD-7.3, 7.0 amd64
>  *                                      FreeBSD-6.4, 6.2 amd64
>  *
>  */
>
> I m better than TESO 7350 see attached.
> I aint mad at cha
> and dont forget that the scene is fucked.
> and that the public scene is fucked too, kind of.
> youse a down ass bitch and I aint mad at cha.
> thanks lsd you are the only one NORMAL.
> hear the track before you see the code:
> http://www.youtube.com/watch?v=krxu9_dRUwQ
> BTW my box (isowarez.de) got hacked so expect me in a zine :>
>
> /Signed "the awesome" Kingcope
>

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] FreeBSD ftpd and ProFTPd on FreeBSD remote r00t exploit

2011-11-30 Thread noreply
Hello there!
The exploit "roaringbeast" will be added to Exploit pack

Authors name and code/license will be respected and it will be ported 
to Python with minimal modifications

The code will be uploaded to Exploit Pack Git Repo and will be 
available to all our users

Thank you and congratulations for such a great job!

JSacco

On 30.11.2011 13:32, HI-TECH . wrote:
> /* KCOPE2011 - x86/amd64 bsd ftpd remote root exploit
>  *
>  * KINGCOPE CONFIDENTIAL - SOURCE MATERIALS
>  *
>  * This is unpublished proprietary source code of KINGCOPE Security.
>  *
>  * (C) COPYRIGHT KINGCOPE Security, 2011
>  * All Rights Reserved
>  *
>
> 
> *
>  * bug found by Kingcope
>  * thanks to noone except alex whose damn down
>  *
>  * tested against:  FreeBSD-8.2,8.1,7.2,7.1 i386;
>  *FreeBSD-6.3 i386
>  *FreeBSD-5.5,5.2 i386
>  *FreeBSD-8.2 amd64
>  *FreeBSD-7.3, 7.0 amd64
>  *FreeBSD-6.4, 6.2 amd64
>  *
>  */
>
> I m better than TESO 7350 see attached.
> I aint mad at cha
> and dont forget that the scene is fucked.
> and that the public scene is fucked too, kind of.
> youse a down ass bitch and I aint mad at cha.
> thanks lsd you are the only one NORMAL.
> hear the track before you see the code:
> http://www.youtube.com/watch?v=krxu9_dRUwQ
> BTW my box (isowarez.de) got hacked so expect me in a zine :>
>
> /Signed "the awesome" Kingcope

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/