Re: [Full-disclosure] Interesting fun with Cisco VPN Client Privilege Escalation Vulnerabilities

2007-08-16 Thread Steven Adair
I went to the below URL you referenced (http://www.cisco.com/cgi-bin/tablebuild.pl/windows?psrtdcat20e2), logged in, and it works fine for me with a listing of all the clients to download. vpnclient-win-msi-5.0.01.0600-k9.exe VPN Client Software for 2000/XP/Vista - Microsoft Installer 5.0.01.0

Re: [Full-disclosure] Interesting fun with Cisco VPN Client Privilege Escalation Vulnerabilities

2007-08-16 Thread J. Oquendo
James Lay wrote: > You'll need a LOT more then just the site and serial number...you'll need to > be registered with Cisco or provide them with: > > REQUIRED INFORMATION > > * CONTACT NAME: > * CONTACT PHONE NUMBER: > * CONTACT CISCO.COM USERID (if one exists): > * CONTACT EMAIL ADDRESS: > * CO

[Full-disclosure] Interesting fun with Cisco VPN Client Privilege Escalation Vulnerabilities

2007-08-16 Thread James Lay
Hey All! So, as an exercise just for giggles, I attempted to get a fix for this. Reference: http://www.cisco.com/warp/public/707/cisco-sa-20070815-vpnclient.shtml As we are just a shop, we do not have a Cisco contract. Here's where the fun starts. From the above: 1. "Customers who purchase