Re: [Full-disclosure] [FDSA] Sort - Critical Format String Vulnerability

2008-01-18 Thread reepex
LOL you are an idiot could you please google format string 101, read the printf man page, and leave security forever On Jan 18, 2008 1:45 AM, Tonnerre Lombard <[EMAIL PROTECTED]> wrote: > Salut, Fredrick, > > On Thu, 17 Jan 2008 12:05:13 -0600 "Fredrick Diggle" > <[EMAIL PROTECTED]> wrote: > > T

Re: [Full-disclosure] [FDSA] Sort - Critical Format String Vulnerability

2008-01-18 Thread Fredrick Diggle
Fredrick Diggle apologizes, he always forgets that exploitation is IMPOSSIBLE if there is no how-to in phrack. Racing your own buffer is hard Lombard so he feels your pain :( Also how dare you accuse Diggle Sec of releasing fake vulnerabilities. Continue down that train of thought and you are like

Re: [Full-disclosure] [FDSA] Sort - Critical Format String Vulnerability

2008-01-18 Thread Joey Mengele
Dear Lombard Retard, Excellent analysis, except it is completely wrong LOLOLOLOL. Try %n. J "Gratitude is a sickness suffered by dogs." - Gadi Evron On Fri, 18 Jan 2008 02:45:41 -0500 Tonnerre Lombard <[EMAIL PROTECTED]> wrote: >Salut, Fredrick, > >On Thu, 17 Jan 2008 12:05:13 -0600 "Fredrick

Re: [Full-disclosure] [FDSA] Sort - Critical Format String Vulnerability

2008-01-18 Thread Tonnerre Lombard
Salut, Fredrick, On Thu, 17 Jan 2008 12:05:13 -0600 "Fredrick Diggle" <[EMAIL PROTECTED]> wrote: > The following output shows a manafestation of this vulnerability: > > C:\>sort %x.%x.%x.%x > 7c812f39.0.0.41414141The system cannot find the file specified. This is actually confirmed on Wi

[Full-disclosure] [FDSA] Sort - Critical Format String Vulnerability

2008-01-17 Thread Fredrick Diggle
### Fredrick Diggle Security Advisory Application: Sort Versions: 5.1.2600.0 verified to be vulnerable Platforms: Microsoft Windows (All Versions) Bugs: Format String Vulnerability Severity: Quite Hig