---------- Forwarded message ----------
From: c0ncept <[EMAIL PROTECTED]>
Subject: format string in ssl dump
Resent-Subject: format string in ssl dump
Date: Fri, 8 Dec 2000 08:43:35 -0800
To: [EMAIL PROTECTED]

Sorry if this has already got posted.

Seeweed found this in ssldump the other day.  The follwoing text is from his
website (http://dropwire.dhs.org/~seeweed/):


SSLDUMP is a program witch is simallar to tcpdump, but also adds encryption
to its network debugging procedures..It captures traffic then decodes it to
stdout ... Overall it is a great program to use when finding out where
something went wrong or just to see what your buddy's encryption he has
choosen to use was

Here is the bug I have found...(the Author has been notified..)

1) Run SSLDUMP (needs you to be root unless setuid)

2)Open Up Netscape Navigator it)

3) Type the following in Netscape Navigator: fixme:%s%s%s%s%s%s


4) watch as ssldump with gather the traffic then segfault..

--c0ncept

______________________________________________________________________
Apache Interface to OpenSSL (mod_ssl)                   www.modssl.org
User Support Mailing List                      [EMAIL PROTECTED]
Automated List Manager                            [EMAIL PROTECTED]

Reply via email to