Re: [Full-disclosure] Microsoft Windows Server Service (MS08-067) Exploit

2008-11-17 Thread buzzedlightyear
not really fair to say "All the vulnerabilities/exploits listed here are 
all researched and discovered by me." on your page when in fact you 
didn't discover this one (didn't check the others listed there).

Debasis Mohanty wrote:
> Having not found one (except msf) that reliably works against my own setup
> thought of writing my own MS08-067 exploit piece. Plugged the shellcode for
> win2k and win2k3[sp2]. No plans for updating the xp shellcode. 
>
> Grab the python here: 
> http://www.hackingspirits.com/vuln-rnd/vuln-rnd.html
>
>
>
> -d
> www.coffeenandsecurity.com
> www.hackingspirits.com
>
>
>
>
> ___
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>
>   

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] Microsoft Windows Server Service (MS08-067) Exploit

2008-11-16 Thread Debasis Mohanty
Point taken! :) 

Actually I wanted to have separate section for putting the exploits I have
published for vulnerabilities already discovered by someone else; but later
thought of putting all in the same page with a note indicating highlighting
those vulnerabilities which are not mine but the exploits are... 

Hence the text is now changed to - 

"All the vulnerabilities/exploits listed here are all researched and
discovered by me except the one highlighted in blue (In this case the
exploit is by me)."


Thanks for pointing out this -d

-Original Message-
From: buzzedlightyear [mailto:[EMAIL PROTECTED] 
Sent: 17 November 2008 08:46
To: Debasis Mohanty
Cc: [EMAIL PROTECTED]
Subject: Re: [Full-disclosure] Microsoft Windows Server Service (MS08-067)
Exploit

not really fair to say "All the vulnerabilities/exploits listed here are 
all researched and discovered by me." on your page when in fact you 
didn't discover this one (didn't check the others listed there).

Debasis Mohanty wrote:
> Having not found one (except msf) that reliably works against my own setup
> thought of writing my own MS08-067 exploit piece. Plugged the shellcode
for
> win2k and win2k3[sp2]. No plans for updating the xp shellcode. 
>
> Grab the python here: 
> http://www.hackingspirits.com/vuln-rnd/vuln-rnd.html
>
>
>
> -d
> www.coffeenandsecurity.com
> www.hackingspirits.com
>
>
>
>
> ___
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>
>   

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


[Full-disclosure] Microsoft Windows Server Service (MS08-067) Exploit

2008-11-16 Thread Debasis Mohanty
Having not found one (except msf) that reliably works against my own setup
thought of writing my own MS08-067 exploit piece. Plugged the shellcode for
win2k and win2k3[sp2]. No plans for updating the xp shellcode. 

Grab the python here: 
http://www.hackingspirits.com/vuln-rnd/vuln-rnd.html



-d
www.coffeenandsecurity.com
www.hackingspirits.com




___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/