"bishan kochher" <[EMAIL PROTECTED]> writes: > i know with nessus we can write some scripts to really exploit and do > something damaging on remote m/c
Yes we can. However, as I am a bad guy, I prefer to write scripts that _crash_ exploitable services. This way, nobody is going to exploit them. There is another good point too: violent generic tests detect unknown vulnerabilities, sometimes. > wat i want is some proper direction from ur side , regarding how to > do it, Easy: for buffer overflows, just replace the calls to crap() by the right shell code. Now your proble is to define what the "right" shell code is...
