Re: [Full-disclosure] [FDSA] Sort - Critical Format String Vulnerability

2008-01-18 Thread Tonnerre Lombard
Salut, Fredrick, On Thu, 17 Jan 2008 12:05:13 -0600 Fredrick Diggle [EMAIL PROTECTED] wrote: The following output shows a manafestation of this vulnerability: C:\sort %x.%x.%x.%x 7c812f39.0.0.41414141The system cannot find the file specified. This is actually confirmed on Windows

Re: [Full-disclosure] [FDSA] Sort - Critical Format String Vulnerability

2008-01-18 Thread Fredrick Diggle
Fredrick Diggle apologizes, he always forgets that exploitation is IMPOSSIBLE if there is no how-to in phrack. Racing your own buffer is hard Lombard so he feels your pain :( Also how dare you accuse Diggle Sec of releasing fake vulnerabilities. Continue down that train of thought and you are

Re: [Full-disclosure] [FDSA] Sort - Critical Format String Vulnerability

2008-01-18 Thread Joey Mengele
Dear Lombard Retard, Excellent analysis, except it is completely wrong LOLOLOLOL. Try %n. J Gratitude is a sickness suffered by dogs. - Gadi Evron On Fri, 18 Jan 2008 02:45:41 -0500 Tonnerre Lombard [EMAIL PROTECTED] wrote: Salut, Fredrick, On Thu, 17 Jan 2008 12:05:13 -0600 Fredrick Diggle

Re: [Full-disclosure] [FDSA] Sort - Critical Format String Vulnerability

2008-01-18 Thread reepex
LOL you are an idiot could you please google format string 101, read the printf man page, and leave security forever On Jan 18, 2008 1:45 AM, Tonnerre Lombard [EMAIL PROTECTED] wrote: Salut, Fredrick, On Thu, 17 Jan 2008 12:05:13 -0600 Fredrick Diggle [EMAIL PROTECTED] wrote: The

[Full-disclosure] [FDSA] Sort - Critical Format String Vulnerability

2008-01-17 Thread Fredrick Diggle
### Fredrick Diggle Security Advisory Application: Sort Versions: 5.1.2600.0 verified to be vulnerable Platforms: Microsoft Windows (All Versions) Bugs: Format String Vulnerability Severity: Quite