Account Options

  1. Sign in
Google Groups Home
« Groups Home
DEFCON 16 and Hacking OpenVMS
There are currently too many topics in this group that display first. To make this topic appear first, remove this option from another topic.
There was an error processing your request. Please try again.
flag
  Messages 1 - 25 of 725 - Collapse all  -  Translate all to Translated (View all originals)   Newer >
The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
 
From:
To:
Cc:
Followup To:
Add Cc | Add Followup-to | Edit Subject
Subject:
Validation:
For verification purposes please type the characters you see in the picture below or the numbers you hear by clicking the accessibility icon. Listen and type the numbers you hear
 
Mark Daniel  
View profile  
 More options Aug 6 2008, 8:10 am
Newsgroups: comp.os.vms
From: Mark Daniel <mark.dan...@vsm.com.au>
Date: Wed, 06 Aug 2008 21:40:56 +0930
Local: Wed, Aug 6 2008 8:10 am
Subject: DEFCON 16 and Hacking OpenVMS
http://www.defcon.org/html/defcon-16/dc-16-speakers.html#Oberg

is due to be presented this Sunday, Aug 10th 2008

Does anyone know ...

o  whether there will be anyone from the VMS community at this event;

o  the content of this presentation;

o  whether the 'proceedings' will be published?

The abstract is protraying the potential exploits as novel and so would
make an interesting read.

--
Ticking away the moments that make up a dull day
You fritter and waste the hours in an offhand way.
Kicking around on a piece of ground in your home town
Waiting for someone or something to show you the way.
[Mason, Waters, Wright, Gilmour; The Dark Side of the Moon]


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
bradhamilton  
View profile  
 More options Aug 6 2008, 6:20 pm
Newsgroups: comp.os.vms
From: bradhamilton <bradhamil...@comcast.net>
Date: Wed, 06 Aug 2008 18:20:54 -0400
Local: Wed, Aug 6 2008 6:20 pm
Subject: Re: DEFCON 16 and Hacking OpenVMS

Mark Daniel wrote:
> http://www.defcon.org/html/defcon-16/dc-16-speakers.html#Oberg

> is due to be presented this Sunday, Aug 10th 2008

> Does anyone know ...

> o  whether there will be anyone from the VMS community at this event;

> o  the content of this presentation;

> o  whether the 'proceedings' will be published?

> The abstract is protraying the potential exploits as novel and so would
> make an interesting read.

You might want to ask the question over at the Deathrow cluster - there
are likely to be some attendees from that group.

 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Mark Daniel  
View profile  
 More options Aug 7 2008, 4:51 am
Newsgroups: comp.os.vms
From: Mark Daniel <mark.dan...@vsm.com.au>
Date: Thu, 07 Aug 2008 18:21:01 +0930
Local: Thurs, Aug 7 2008 4:51 am
Subject: Re: DEFCON 16 and Hacking OpenVMS

I could also post on the relevant ITRC forum but VMS vulnerabilities
likely would be considered off-topic and it end up expunged!

--
Tired of lying in the sunshine staying home to watch the rain.
You are young and life is long and there is time to kill today.
And then one day you find ten years have got behind you.
No one told you when to run, you missed the starting gun.
[Mason, Waters, Wright, Gilmour; The Dark Side of the Moon]


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
samp...@gmail.com  
View profile  
 More options Aug 7 2008, 12:31 pm
Newsgroups: comp.os.vms
From: samp...@gmail.com
Date: Thu, 7 Aug 2008 09:31:58 -0700 (PDT)
Local: Thurs, Aug 7 2008 12:31 pm
Subject: Re: DEFCON 16 and Hacking OpenVMS
There's apparently an overflow flat in Multinet's Fingerd as well:

http://seclists.org/bugtraq/2008/Aug/0056.html


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Mark Daniel  
View profile  
 More options Aug 7 2008, 2:15 pm
Newsgroups: comp.os.vms
From: Mark Daniel <mark.dan...@vsm.com.au>
Date: Fri, 08 Aug 2008 03:45:19 +0930
Local: Thurs, Aug 7 2008 2:15 pm
Subject: Re: DEFCON 16 and Hacking OpenVMS

samp...@gmail.com wrote:
> There's apparently an overflow flat in Multinet's Fingerd as well:

> http://seclists.org/bugtraq/2008/Aug/0056.html

This appears to behave as described on at least VAX VMS V7.3 MultiNet
V5.1 Rev A-X but not on Alpha VMS V8.3 V5.2 Rev A-X or I64 VMS V8.3 V5.2
Rev A-X (three platforms I have access to).

$ echo `perl -e 'print "a"x1000'` | nc -v host.name 79
Connection to host.name 79 port [tcp/finger] succeeded!

I guess we can assume the 'group of lads' would be keeping an occasional
eye on c.o.v. :-)

--
So you run and you run to catch up with the sun but it's sinking
Racing around to come up behind you again.
The sun is the same in a relative way but you're older,
Shorter of breath and one day closer to death.
[Mason, Waters, Wright, Gilmour; The Dark Side of the Moon]


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
William Webb  
View profile  
 More options Aug 7 2008, 8:11 pm
Newsgroups: comp.os.vms
From: "William Webb" <william.w.w...@gmail.com>
Date: Thu, 7 Aug 2008 20:11:23 -0400
Local: Thurs, Aug 7 2008 8:11 pm
Subject: Re: DEFCON 16 and Hacking OpenVMS

The last "black hat" stuff I read (and it was a while ago) was quite
outdated and went back to the days when SYSTEM, FIELD, etc had default
passwords set at installation time.

That's no longer the case, and has been for some time.

WWWebb


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
bradhamilton  
View profile  
 More options Aug 7 2008, 8:37 pm
Newsgroups: comp.os.vms
From: bradhamilton <bradhamil...@comcast.net>
Date: Thu, 07 Aug 2008 20:37:17 -0400
Local: Thurs, Aug 7 2008 8:37 pm
Subject: Re: DEFCON 16 and Hacking OpenVMS

Mark Daniel wrote:
> http://www.defcon.org/html/defcon-16/dc-16-speakers.html#Oberg

> is due to be presented this Sunday, Aug 10th 2008

> Does anyone know ...

> o  whether there will be anyone from the VMS community at this event;

> o  the content of this presentation;

> o  whether the 'proceedings' will be published?

> The abstract is protraying the potential exploits as novel and so would
> make an interesting read.

I will wait for this weekend, like some of us, but in the meantime, I
will note that one of the presenters claims to have an interest in
"social engineering".  Of course, the abstract promises "0day
vulnerabilities", but we will have to wait and see.

 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Bob Koehler  
View profile  
 More options Aug 8 2008, 8:49 am
Newsgroups: comp.os.vms
From: koeh...@eisner.nospam.encompasserve.org (Bob Koehler)
Date: 8 Aug 2008 07:49:44 -0500
Local: Fri, Aug 8 2008 8:49 am
Subject: Re: DEFCON 16 and Hacking OpenVMS
In article <8660a3a10808071711y49326bci2d6514c28357e...@mail.gmail.com>, "William Webb" <william.w.w...@gmail.com> writes:

> The last "black hat" stuff I read (and it was a while ago) was quite
> outdated and went back to the days when SYSTEM, FIELD, etc had default
> passwords set at installation time.

> That's no longer the case, and has been for some time.

   There's a fairly easy to find (or it was last time I bothered
   looking) guide to hacking VMS that I think you're talking about.

   It was written to a default installation and bad system management
   prior to VMS 5.0.  It used the canned passwords to get access to
   a privileged account.  It told of all kinds of little things a
   privileged account could do.

   Unless the DEFCON sessions reports ways to access a system without
   authorization, or elevate your privileges to a higher class without
   authorization, on a properly installed and managed system, it's just
   smoke up your virtual skirt.

   We wait to see.


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Simon Clubley  
View profile  
 More options Aug 11 2008, 7:40 am
Newsgroups: comp.os.vms
From: clubley@remove_me.eisner.decus.org-Earth .UFP (Simon Clubley)
Date: 11 Aug 2008 06:40:37 -0500
Local: Mon, Aug 11 2008 7:40 am
Subject: Re: DEFCON 16 and Hacking OpenVMS

In article <00a990b4$0$20308$c3e8...@news.astraweb.com>, Mark Daniel <mark.dan...@vsm.com.au> writes:
> http://www.defcon.org/html/defcon-16/dc-16-speakers.html#Oberg

> is due to be presented this Sunday, Aug 10th 2008

Does anyone know what happened with this ?

Thanks,

Simon.

--
Simon Clubley, clubley@remove_me.eisner.decus.org-Earth.UFP
Microsoft: Bringing you 1980's technology to a 21st century world


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
patrick jankowiak  
View profile  
 More options Aug 11 2008, 10:47 pm
Newsgroups: comp.os.vms
From: patrick jankowiak <e...@swbell.net>
Date: Mon, 11 Aug 2008 21:47:38 -0500
Local: Mon, Aug 11 2008 10:47 pm
Subject: Re: DEFCON 16 and Hacking OpenVMS
I guess they are still "challenged" by the "rout of '01", delivered
handily by OpenVMS on Alpha courtesy of The Wiz, Coremac, and Opcom; the
legend of which is chronicled here:
http://www.bunkerofdoom.com/defcon/defcon9.html

-or maybe they forgot about it and this is completely new.
The rules of the 'game' were changed forever. But never mind;

By the time I saw it, it was too late to get in the truck and drive to
the DEFCON by myself.

Patrick J.


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
patrick jankowiak  
View profile  
 More options Aug 11 2008, 11:13 pm
Newsgroups: comp.os.vms
From: patrick jankowiak <e...@swbell.net>
Date: Mon, 11 Aug 2008 22:13:34 -0500
Local: Mon, Aug 11 2008 11:13 pm
Subject: Re: DEFCON 16 and Hacking OpenVMS
this also, of the past..
http://www.openvms.org/stories.php?story=07/05/18/5543122

just to pass some time till someone can report.


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
William Webb  
View profile  
 More options Aug 12 2008, 12:06 am
Newsgroups: comp.os.vms
From: "William Webb" <william.w.w...@gmail.com>
Date: Tue, 12 Aug 2008 00:06:44 -0400
Local: Tues, Aug 12 2008 12:06 am
Subject: Re: DEFCON 16 and Hacking OpenVMS

Hi, Pat-

Good to see you posting.  "What I Did On My Summer Vacation" is one of the
funniest VMS stories I've ever heard, and I've heard some Real Funny Ones at
"Magic Night" at the last two bootcamps.

WWWebb


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
patrick jankowiak  
View profile  
 More options Aug 12 2008, 2:01 am
Newsgroups: comp.os.vms
From: patrick jankowiak <e...@swbell.net>
Date: Tue, 12 Aug 2008 01:01:55 -0500
Local: Tues, Aug 12 2008 2:01 am
Subject: Re: DEFCON 16 and Hacking OpenVMS

Hi William,

Thank you and I guess I need to show up to the party from time to time.
I guess I sort of navigated past the edge of the known world, and found
more worlds and adventures to explore.


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
samp...@gmail.com  
View profile  
 More options Aug 12 2008, 9:58 am
Newsgroups: comp.os.vms
From: samp...@gmail.com
Date: Tue, 12 Aug 2008 06:58:40 -0700 (PDT)
Local: Tues, Aug 12 2008 9:58 am
Subject: Re: DEFCON 16 and Hacking OpenVMS
Guys,

I just finished reading the presenation slides from DEFCON and
fortunately it doesn't to be anything earth-shattering, two exploits
are described:

1. A format string vulnerability in the FINGER client (VAX only). The
example shellcode is stored on a remote system's .plan file and forces
the victim FINGER client to modify SYSUAF.

2. A CLI buffer overflow on Alphas. Basically any input over 511
characters causes an overflow, it seems to be possible to have a
privileged process execute arbitrary code.

Anyway, this is from a 10 minute reading of the slides, I might have
missed something, but the important thing (IMHO) is that neither of
these exploits are possible from remote but require a malicious user
to already have an account on the targeted system.

Sampsa


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
davi...@alpha2.mdx.ac.uk  
View profile  
 More options Aug 12 2008, 10:49 am
Newsgroups: comp.os.vms
From: davi...@alpha2.mdx.ac.uk
Date: Tue, 12 Aug 2008 14:49:51 +0000 (UTC)
Local: Tues, Aug 12 2008 10:49 am
Subject: Re: DEFCON 16 and Hacking OpenVMS
In article <6419afac-bb99-4d7d-b61c-2e29234df...@z72g2000hsb.googlegroups.com>, samp...@gmail.com writes:

>Guys,

>I just finished reading the presenation slides from DEFCON and
>fortunately it doesn't to be anything earth-shattering, two exploits
>are described:

>1. A format string vulnerability in the FINGER client (VAX only). The
>example shellcode is stored on a remote system's .plan file and forces
>the victim FINGER client to modify SYSUAF.

Is this with DEC TCPIP services or is it something to do with the
Multinet finger vulnerability ?

see

http://www.multinet.process.com/scripts/eco/eco_tlb.com?FINGER-010_A052

>2. A CLI buffer overflow on Alphas. Basically any input over 511
>characters causes an overflow, it seems to be possible to have a
>privileged process execute arbitrary code.

Can you explain this one in a bit more detail ?
Is this an attack against DCL itself, images installed with privileges
or something else ?

David Webb
Security team leader
CCSS
Middlesex University


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
samp...@gmail.com  
View profile  
 More options Aug 12 2008, 11:27 am
Newsgroups: comp.os.vms
From: samp...@gmail.com
Date: Tue, 12 Aug 2008 08:27:47 -0700 (PDT)
Local: Tues, Aug 12 2008 11:27 am
Subject: Re: DEFCON 16 and Hacking OpenVMS

> >1. A format string vulnerability in the FINGER client (VAX only). The
> >example shellcode is stored on a remote system's .plan file and forces
> >the victim FINGER client to modify SYSUAF.

> Is this with DEC TCPIP services or is it something to do with the
> Multinet finger vulnerability ?

It appears to be something separate, since it seems to have to do with
a format string
vulnerability. Basically someone puts a bunch of % strings and
shellcode in their .plan
on a remote host, fingers that user from the target host, and the
FINGER client executes
the shellcode due to the format string vulnerability in the client.

> >2. A CLI buffer overflow on Alphas. Basically any input over 511
> >characters causes an overflow, it seems to be possible to have a
> >privileged process execute arbitrary code.

> Can you explain this one in a bit more detail ?
> Is this an attack against DCL itself, images installed with privileges
> or something else ?

I think this might be a DCL issue, it seems to work across a number of
different images. Not had a chance to play with this as my own VMS
box is down at the moment.

Sampsa


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Bob Koehler  
View profile  
 More options Aug 12 2008, 12:58 pm
Newsgroups: comp.os.vms
From: koeh...@eisner.nospam.encompasserve.org (Bob Koehler)
Date: 12 Aug 2008 11:58:47 -0500
Local: Tues, Aug 12 2008 12:58 pm
Subject: Re: DEFCON 16 and Hacking OpenVMS
In article <6419afac-bb99-4d7d-b61c-2e29234df...@z72g2000hsb.googlegroups.com>, samp...@gmail.com writes:

> Guys,

> 1. A format string vulnerability in the FINGER client (VAX only). The
> example shellcode is stored on a remote system's .plan file and forces
> the victim FINGER client to modify SYSUAF.

   Do they say which finger client?  HPs?

 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Bob Koehler  
View profile  
 More options Aug 12 2008, 1:00 pm
Newsgroups: comp.os.vms
From: koeh...@eisner.nospam.encompasserve.org (Bob Koehler)
Date: 12 Aug 2008 12:00:02 -0500
Local: Tues, Aug 12 2008 1:00 pm
Subject: Re: DEFCON 16 and Hacking OpenVMS
In article <6419afac-bb99-4d7d-b61c-2e29234df...@z72g2000hsb.googlegroups.com>, samp...@gmail.com writes:

> Guys,

> I just finished reading the presenation slides from DEFCON and
> fortunately it doesn't to be anything earth-shattering, two exploits
> are described:

   Are these publically available?  (If there is anything in them, I'd
   like to review my systems).

 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
samp...@gmail.com  
View profile  
 More options Aug 12 2008, 1:26 pm
Newsgroups: comp.os.vms
From: samp...@gmail.com
Date: Tue, 12 Aug 2008 10:26:13 -0700 (PDT)
Local: Tues, Aug 12 2008 1:26 pm
Subject: Re: DEFCON 16 and Hacking OpenVMS
On Aug 12, 6:00 pm, koeh...@eisner.nospam.encompasserve.org (Bob

Koehler) wrote:
> In article <6419afac-bb99-4d7d-b61c-2e29234df...@z72g2000hsb.googlegroups.com>, samp...@gmail.com writes:

> > Guys,

> > I just finished reading the presenation slides from DEFCON and
> > fortunately it doesn't to be anything earth-shattering, two exploits
> > are described:

>    Are these publically available?  (If there is anything in them, I'd
>    like to review my systems).

I got them from a friend who's colleague was at DEFCON - I don't know
what the distribution/copyright issues are with the document so I
daren't host them on my web page.

Sampsa


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
patrick jankowiak  
View profile  
 More options Aug 12 2008, 8:44 pm
Newsgroups: comp.os.vms
From: patrick jankowiak <e...@swbell.net>
Date: Tue, 12 Aug 2008 19:44:55 -0500
Local: Tues, Aug 12 2008 8:44 pm
Subject: Re: DEFCON 16 and Hacking OpenVMS

I would have thought a CLI overflow to have been tried by at least a few
at DEFCON9 because the system automagically created service-rich user
accounts with of course DCL which the hackers were then free to abuse.

We were not scrutinizing buffers however and any such overflow may in
our case have done nothing harmful (by luck or design). I think it was
version 7.1-? if it makes a difference. Did the gentleman specify any
versions?

Patrick J


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
samp...@gmail.com  
View profile  
 More options Aug 13 2008, 4:22 am
Newsgroups: comp.os.vms
From: samp...@gmail.com
Date: Wed, 13 Aug 2008 01:22:14 -0700 (PDT)
Local: Wed, Aug 13 2008 4:22 am
Subject: Re: DEFCON 16 and Hacking OpenVMS

> I would have thought a CLI overflow to have been tried by at least a few
> at DEFCON9 because the system automagically created service-rich user
> accounts with of course DCL which the hackers were then free to abuse.

> We were not scrutinizing buffers however and any such overflow may in
> our case have done nothing harmful (by luck or design). I think it was
> version 7.1-? if it makes a difference. Did the gentleman specify any
> versions?

Default 8.3 install on an Alpha according to the presentation notes.
To reproduce this, apparently one is to enter exactly 511 characters
of input, then press the up arrow three times and wait - a core dump
follows.

Sampsa


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
bradhamilton  
View profile  
 More options Aug 13 2008, 7:12 am
Newsgroups: comp.os.vms
From: bradhamilton <bradhamil...@comcast.net>
Date: Wed, 13 Aug 2008 07:12:36 -0400
Local: Wed, Aug 13 2008 7:12 am
Subject: Re: DEFCON 16 and Hacking OpenVMS

samp...@gmail.com wrote:
>> I would have thought a CLI overflow to have been tried by at least a few
>> at DEFCON9 because the system automagically created service-rich user
>> accounts with of course DCL which the hackers were then free to abuse.

>> We were not scrutinizing buffers however and any such overflow may in
>> our case have done nothing harmful (by luck or design). I think it was
>> version 7.1-? if it makes a difference. Did the gentleman specify any
>> versions?

> Default 8.3 install on an Alpha according to the presentation notes.
> To reproduce this, apparently one is to enter exactly 511 characters
> of input, then press the up arrow three times and wait - a core dump
> follows.

Sorry - I can't reproduce this the way it is described here on my V8.3
Alpha.  After entering the characters, and pressing the up arrow three
times, I am returned to the "$", without a dump.  I have reproduced this
technique on two different Alphas, both running V8.3, and have not
reproduced the reported behavior.

It will be interesting to see the slides.


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
vaxm...@sendspamhere.org  
View profile  
 More options Aug 13 2008, 7:30 am
Newsgroups: comp.os.vms
From: VAXman- @SendSpamHere.ORG
Date: Wed, 13 Aug 2008 11:30:15 GMT
Local: Wed, Aug 13 2008 7:30 am
Subject: Re: DEFCON 16 and Hacking OpenVMS
In article <9781c047-761a-4923-9aab-8c1a32ff7...@x35g2000hsb.googlegroups.com>, samp...@gmail.com writes:

>> I would have thought a CLI overflow to have been tried by at least a few
>> at DEFCON9 because the system automagically created service-rich user
>> accounts with of course DCL which the hackers were then free to abuse.

>> We were not scrutinizing buffers however and any such overflow may in
>> our case have done nothing harmful (by luck or design). I think it was
>> version 7.1-? if it makes a difference. Did the gentleman specify any
>> versions?

>Default 8.3 install on an Alpha according to the presentation notes.
>To reproduce this, apparently one is to enter exactly 511 characters
>of input, then press the up arrow three times and wait - a core dump
>follows.

I know you didn't make the claim but you should first test it out before
brandishing bullshit here.

I've tried to reproduce the claimed results from your posted instruction
and it does NOT produce a "core dump".

--
VAXman- A Bored Certified VMS Kernel Mode Hacker      VAXman(at)TMESIS(dot)COM

... pejorative statements of opinion are entitled to constitutional protection
no matter how extreme, vituperous, or vigorously expressed they may be. (NJSC)

Copr. 2008 Brian Schenkenberger.  Publication of _this_ usenet article outside
of usenet _must_ include its contents in its entirety including this copyright
notice, disclaimer and quotations.


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
samp...@gmail.com  
View profile  
 More options Aug 13 2008, 7:56 am
Newsgroups: comp.os.vms
From: samp...@gmail.com
Date: Wed, 13 Aug 2008 04:56:05 -0700 (PDT)
Local: Wed, Aug 13 2008 7:56 am
Subject: Re: DEFCON 16 and Hacking OpenVMS

> >Default 8.3 install on an Alpha according to the presentation notes.
> >To reproduce this, apparently one is to enter exactly 511 characters
> >of input, then press the up arrow three times and wait - a core dump
> >follows.

> I know you didn't make the claim but you should first test it out before
> brandishing bullshit here.

> I've tried to reproduce the claimed results from your posted instruction
> and it does NOT produce a "core dump".

Hey don't shoot the messenger, people were interested in what was in
the presentation, I just relayed that information WITH THE CAVEAT THAT
I DIDN'T TEST IT. They had screenshots of the flaw and source code for
an exploit, based on that I assumed it's genuine even if we haven't
been able to reproduce it.

I'm not trying to scaremonger or stir up shit, in fact I stated in my
original post that neither of these exploits seemed particularly earth
shattering.

Sampsa


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
William Webb  
View profile  
 More options Aug 13 2008, 8:38 am
Newsgroups: comp.os.vms
From: "William Webb" <william.w.w...@gmail.com>
Date: Wed, 13 Aug 2008 08:38:13 -0400
Local: Wed, Aug 13 2008 8:38 am
Subject: Re: DEFCON 16 and Hacking OpenVMS

There are people in Engineering with whom I can check...

WWWebb


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Messages 1 - 25 of 725   Newer >
« Back to Discussions « Newer topic     Older topic »