I'm very quiet on this list but this one was a LOL thread, literally.

Thanks for the pick-me-up on a random Wednesday morning.


-----Original Message-----
From: Michel Arboi [mailto:[EMAIL PROTECTED]]
Sent: Wednesday, January 22, 2003 7:59 AM
To: bishan kochher
Cc: [EMAIL PROTECTED]
Subject: Re: how to gain root shell,buffer overflows using nasl..


"bishan kochher" <[EMAIL PROTECTED]> writes:

> i know with nessus we can write some scripts to really exploit and do
> something damaging on remote m/c 

Yes we can. However, as I am a bad guy, I prefer to write scripts that
_crash_ exploitable services. This way, nobody is going to exploit
them.
There is another good point too: violent generic tests detect unknown
vulnerabilities, sometimes.

> wat i want is some proper direction from ur side , regarding how to
> do it, 

Easy: for buffer overflows, just replace the calls to crap() by the 
right shell code. 
Now your proble is to define what the "right" shell code is...

Reply via email to