bf1942 exploit kills server

Michiel Brandenburg michielb at stack.nl
Wed Feb 26 19:18:34 EST 2003


Hello Daniel,

Wednesday, February 26, 2003, 10:54:43 PM, you wrote:


DV> ----- Original Message -----
DV> From: "Brad Davidson" <kiloman at oatmail.org>
DV> To: <bf1942 at icculus.org>
DV> Sent: Wednesday, February 26, 2003 3:43 PM
DV> Subject: Re: [bf1942] bf1942 exploit


>> Daniel Valois said:
>> > http://archives.neohapsis.com/archives/bugtraq/2003-02/0342.html

>> Would be nice if the SOB had tested with a modern version of BF. Rconsole
>> on 1.2 sucked ass in general, I'm sure there's a lot more stuff that could
>> kill it. Shit, I could kill it by using their actual rconsole tool
>> occasionally.
>>
>> If you're worried about it right now, set up an IPFilter rule that only
>> allows connections to the rconsole port from certain IPs that you trust,
>> or use TCP Wrappers to do the same.

Tryed it on the latest server.
result:
Program terminated with signal 11, Segmentation fault.
BackTrace:

#0  0x0962188e in ?? ()
#1  0x09511dda in ?? ()
#2  0x0906b2f4 in ?? ()
#3  0x08681ce3 in ?? ()
#4  0x08681031 in ?? ()
#5  0x0863241a in ?? ()
#6  0x25893589 in __libc_start_main () from /lib/i686/libc.so.6


references: http://archives.neohapsis.com/archives/bugtraq/2003-02/0342.html

-- 
Best regards,
 Michiel                            mailto:michielb at stack.nl





More information about the Bf1942 mailing list