Re: Sniffing SSH and HTTPS

2001-09-01 Thread Rob Zietlow
My buddy and I have been playing with this on our BSD boxes and it's a "cool" little tool. It's made for purposes of good, but we know everyone won't. It's does the monkey in the middle attack. As pointed out earlier, it does arp poisoning in cases like this. Once you fire up ettercap yo

Re: Sniffing SSH and HTTPS

2001-09-01 Thread Rob Zietlow
My buddy and I have been playing with this on our BSD boxes and it's a "cool" little tool. It's made for purposes of good, but we know everyone won't. It's does the monkey in the middle attack. As pointed out earlier, it does arp poisoning in cases like this. Once you fire up ettercap y

Re: CGI Buffer Overflow?

2001-07-19 Thread zietlow
Welcome to the wonderful world of the new IIS exploit > Anyone seen this before? I have looked around for similar attacks, but > cannot find any info. I assume that is a unicode string padded out with > Ns. How would I go about finding out what is in the string? > > > xxx.xxx.xxx.xxx - - [19/

Re: CGI Buffer Overflow?

2001-07-19 Thread zietlow
Welcome to the wonderful world of the new IIS exploit > Anyone seen this before? I have looked around for similar attacks, but > cannot find any info. I assume that is a unicode string padded out with > Ns. How would I go about finding out what is in the string? > > > xxx.xxx.xxx.xxx - - [19