<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>uncompiled.com &#187; Bugs</title>
	<atom:link href="http://www.uncompiled.com/category/bugs/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.uncompiled.com</link>
	<description>Technology News That You Need</description>
	<lastBuildDate>Fri, 30 Jul 2010 01:19:58 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>New w3af release!</title>
		<link>http://www.uncompiled.com/2010/03/new-w3af-release/</link>
		<comments>http://www.uncompiled.com/2010/03/new-w3af-release/#comments</comments>
		<pubDate>Wed, 31 Mar 2010 14:13:07 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Bugs]]></category>
		<category><![CDATA[Education]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Open-Source]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=965</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>    The development team is proud to announce a new w3af release! Some<br />
of the features of the 1.0-rc3 version are:</p>
<p>* Enhanced GUI, including huge changes in the MITM proxy and the Fuzzy<br />
Request Editor<br />
* Increased speed by rewriting parts of the thread management code<br />
* Fixed tons of bugs<br />
* Reduced memory usage<br />
* Many plugins were rewritten using different techniques that use less<br />
HTTP requests to identify the same vulnerabilities<br />
* Reduced false positives</p>
<p>    You can download the latest versions from the official w3af<br />
website:    http://w3af.sf.net/    , enjoy!</p>
<p>    Regarding the project itself, we realized that the time between<br />
each release were totally random, so we reorganized [0] the whole<br />
project in such a way that will force us to release periodically (or<br />
look bad if we don&#8217;t). Contributing [1] is easier than ever, as we<br />
have defined clear ways of finding your tasks with categories,<br />
releases, etc.</p>
<p>    All projects have longstanding bugs, and w3af isn&#8217;t the exception.<br />
I would like to ask for the help of the community to fix two very<br />
critical and complicated bugs [2][3] before we release the 1.0 version<br />
in three months time. If you&#8217;ve got the Python experience, and a<br />
couple of hours&#8230; please give it a try :)</p>
<p><a href="http://seclists.org/fulldisclosure/2010/Mar/544">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/03/new-w3af-release/&amp;n=New+w3af+release%21&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/03/new-w3af-release/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/03/new-w3af-release/&amp;title=New+w3af+release%21" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/03/new-w3af-release/&amp;t=New+w3af+release%21" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/03/new-w3af-release/&amp;title=New+w3af+release%21" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/03/new-w3af-release/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/03/new-w3af-release/&amp;title=New+w3af+release%21&amp;srcUrl=http://www.uncompiled.com/2010/03/new-w3af-release/&amp;srcTitle=New+w3af+release%21&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/03/new-w3af-release/&amp;title=New+w3af+release%21&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22New%20w3af%20release%21%22&amp;body=Link: http://www.uncompiled.com/2010/03/new-w3af-release/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/03/new-w3af-release/&amp;t=New+w3af+release%21" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/03/new-w3af-release/&amp;title=New+w3af+release%21&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/03/new-w3af-release/&amp;title=New+w3af+release%21" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/03/new-w3af-release/&amp;title=New+w3af+release%21" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/03/new-w3af-release/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=New+w3af+release%21+-+http://b2l.me/mta3t&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/03/new-w3af-release/&amp;submitHeadline=New+w3af+release%21&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=New+w3af+release%21&amp;body=Link: http://www.uncompiled.com/2010/03/new-w3af-release/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/03/new-w3af-release/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>FreeBSD and OpenBSD ftpd bug (not exploitable?)</title>
		<link>http://www.uncompiled.com/2010/03/freebsd-and-openbsd-ftpd-bug-not-exploitable/</link>
		<comments>http://www.uncompiled.com/2010/03/freebsd-and-openbsd-ftpd-bug-not-exploitable/#comments</comments>
		<pubDate>Mon, 08 Mar 2010 16:25:53 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[BSD]]></category>
		<category><![CDATA[Bugs]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[Vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=853</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>FreeBSD ftpd globbing bug &#8211; null pointer dereference ?</p>
<p>Affected FreeBSD Releases<br />
+-+-+-+-+-+-+-+-+-+<br />
FreeBSD 8.0, 6.3 and 4.9</p>
<p>Affected OpenBSD Releases<br />
+-+-+-+-+-+-+-+-+-+<br />
OpenBSD 4.6</p>
<p>Testing Environment<br />
+-+-+-+-+-+-+-+-+-+<br />
FreeBSD localhost.Belkin 8.0-RELEASE FreeBSD 8.0-RELEASE #0: Sat Nov 21<br />
15:48:17 UTC 2009<br />
root () almeida cse buffalo edu:/usr/obj/usr/src/sys/GENERIC  i386</p>
<p>Full Description<br />
+-+-+-+-+-+-+-+-+-+<br />
FreeBSD (tested back to 4.9-Release) (and OpenBSD 4.6) has a bug in its<br />
ftpd when handling globbing requests.</p>
<p>My investigation results in this being a null pointer dereference in<br />
popen.c.<br />
I am not sure if this could be a heap overrun, but I don&#8217;t think so.</p>
<p>from popen.c:</p>
<p>        /* glob each piece */<br />
        gargv[0] = argv[0];<br />
        for (gargc = argc = 1; argv[argc] &#038;&#038; gargc < (MAXGLOBARGS-1); argc++) {<br />
                glob_t gl;<br />
                int flags = GLOB_BRACE|GLOB_NOCHECK|GLOB_TILDE;</p>
<p>                memset(&#038;gl, 0, sizeof(gl));<br />
                gl.gl_matchc = MAXGLOBARGS;<br />
                flags |= GLOB_LIMIT;<br />
[1]             if (glob(argv[argc], flags, NULL, &#038;gl))<br />
                        gargv[gargc++] = strdup(argv[argc]);<br />
[2]             else<br />
[3]                     for (pop = gl.gl_pathv; *pop &#038;&#038; gargc < (MAXGLOBARGS-1);<br />
                             pop++)<br />
                                gargv[gargc++] = strdup(*pop);<br />
                globfree(&#038;gl);<br />
        }</p>
<p>At [1] glob() is called. if theres a long directory (for example "A" x<br />
200) and a request like described<br />
in "how to repeat this problem" is sent to the ftpd it crashes. My<br />
assumption is because it lands in the<br />
else clause [2], glob doesn't fail but gives back a zeroed out gl<br />
structure. In [3] then there's no check<br />
if pop is null and therefore *pop gets dereferenced which is a null<br />
pointer and the ftpd instance crashes.</p>
<p>Could someone please shed some light into why glob doesn't fail but<br />
gives a zeroed out structure back?</p>
<p>How to repeat the problem<br />
+-+-+-+-+-+-+-+-+-+-+-+-+-+</p>
<p>$ ftp 192.168.2.11<br />
Connected to 192.168.2.11.<br />
220 localhost.Belkin FTP server (Version 6.00LS) ready.<br />
Name (192.168.2.11:nr): kcope<br />
331 Password required for kcope.<br />
Password:<br />
230 User kcope logged in.<br />
Remote system type is UNIX.<br />
Using binary mode to transfer files.<br />
ftp> mkdir<br />
WWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWW<br />
257<br />
&#8220;WWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWW&#8221;<br />
 directory created.<br />
ftp> ls {W*/../W*/../W*/../W*/../W*/../W*/../W*/}<br />
200 PORT command successful.<br />
&#8212;snip&#8212;</p>
<p>on the other side:</p>
<p>&#8212;snip&#8212;<br />
0x282261e5 in read () at read.S:3<br />
3       RSYSCALL(read)<br />
Current language:  auto; currently asm<br />
(gdb) c<br />
Continuing.</p>
<p>Program received signal SIGSEGV, Segmentation fault.<br />
0x0805622c in getline ()<br />
(gdb) i r<br />
eax            0&#215;0      0<br />
ecx            0&#215;0      0<br />
edx            0&#215;0      0<br />
ebx            0xbfbfd911       -1077946095<br />
esp            0xbfbfba70       0xbfbfba70<br />
ebp            0xbfbfcc08       0xbfbfcc08<br />
esi            0&#215;1      1<br />
edi            0xbfbfcbf4       -1077949452<br />
eip            0x805622c        0x805622c<br />
eflags         0&#215;10293  66195<br />
cs             0&#215;33     51<br />
ss             0x3b     59<br />
ds             0x3b     59<br />
es             0x3b     59<br />
fs             0x3b     59<br />
gs             0x1b     27<br />
(gdb) x/10i $eip<br />
0x805622c <getline +12620>:      mov    (%edx),%eax<br />
0x805622e </getline><getline +12622>:      setle  %cl<br />
0&#215;8056231 </getline><getline +12625>:      mov    %ecx,%esi<br />
0&#215;8056233 </getline><getline +12627>:      test   %eax,%eax<br />
0&#215;8056235 </getline><getline +12629>:      je     0&#215;8056281 </getline><getline +12705><br />
0&#215;8056237 </getline><getline +12631>:      test   %cl,%cl<br />
0&#215;8056239 </getline><getline +12633>:      je     0&#215;8056281 </getline><getline +12705><br />
0x805623b </getline><getline +12635>:      mov    %edx,%ebx<br />
0x805623d </getline><getline +12637>:      mov    0xffffee7c(%ebp),%edx<br />
0&#215;8056243 </getline><getline +12643>:      lea    0xffffee90(%ebp,%edx,4),%edi<br />
(gdb) i f<br />
Stack level 0, frame at 0xbfbfcc10:<br />
 eip = 0x805622c in getline; saved eip 0x805047b<br />
 called by frame at 0xbfbfcc14<br />
 Arglist at 0xbfbfcc08, args:<br />
 Locals at 0xbfbfcc08, Previous frame&#8217;s sp is 0xbfbfcc10<br />
 Saved registers:<br />
  ebx at 0xbfbfcbfc, ebp at 0xbfbfcc08, esi at 0xbfbfcc00, edi at<br />
0xbfbfcc04,<br />
  eip at 0xbfbfcc0c<br />
(gdb) </p>
<p>Testing program:</p>
<p>&#8212;snip&#8212;</p>
<p>#include <glob .h><br />
#include <stdio .h></p>
<p>#define MAXUSRARGS      100<br />
#define MAXGLOBARGS     1000</p>
<p>void do_glob() {<br />
        glob_t gl;<br />
        char **pop;</p>
<p>        char buffer[256];<br />
        strcpy(buffer, &#8220;{A*/../A*/../A*/../A*/../A*/../A*/../A*}&#8221;);</p>
<p>        int flags = GLOB_BRACE|GLOB_NOCHECK|GLOB_TILDE;<br />
        memset(&#038;gl, 0, sizeof(gl));<br />
        gl.gl_matchc = MAXGLOBARGS;<br />
        flags |= GLOB_LIMIT;<br />
        if (glob(buffer, flags, NULL, &#038;gl)) {<br />
                printf(&#8220;GLOB FAILED!\n&#8221;);<br />
                return 0;<br />
        }<br />
        else<br />
//                for (pop = gl.gl_pathv; pop &#038;&#038; *pop &#038;&#038; 1 < (MAXGLOBARGS-1);<br />
                for (pop = gl.gl_pathv; *pop &#038;&#038; 1 < (MAXGLOBARGS-1);<br />
                     pop++) {<br />
                        printf("glob success");<br />
                        return 0;<br />
                }<br />
        globfree(&#038;gl);<br />
}</p>
<p>main(int argc, char **argv) {<br />
        do_glob();<br />
        do_glob();<br />
}<br />
---snip---</p>
<p>05 March 2010<br />
/kingcope</p>
<p><a href="http://seclists.org/fulldisclosure/2010/Mar/117">Source      </stdio></glob></getline></p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/03/freebsd-and-openbsd-ftpd-bug-not-exploitable/&amp;n=FreeBSD+and+OpenBSD+ftpd+bug+%28not+exploitable%3F%29+&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/03/freebsd-and-openbsd-ftpd-bug-not-exploitable/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/03/freebsd-and-openbsd-ftpd-bug-not-exploitable/&amp;title=FreeBSD+and+OpenBSD+ftpd+bug+%28not+exploitable%3F%29+" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/03/freebsd-and-openbsd-ftpd-bug-not-exploitable/&amp;t=FreeBSD+and+OpenBSD+ftpd+bug+%28not+exploitable%3F%29+" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/03/freebsd-and-openbsd-ftpd-bug-not-exploitable/&amp;title=FreeBSD+and+OpenBSD+ftpd+bug+%28not+exploitable%3F%29+" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/03/freebsd-and-openbsd-ftpd-bug-not-exploitable/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/03/freebsd-and-openbsd-ftpd-bug-not-exploitable/&amp;title=FreeBSD+and+OpenBSD+ftpd+bug+%28not+exploitable%3F%29+&amp;srcUrl=http://www.uncompiled.com/2010/03/freebsd-and-openbsd-ftpd-bug-not-exploitable/&amp;srcTitle=FreeBSD+and+OpenBSD+ftpd+bug+%28not+exploitable%3F%29+&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/03/freebsd-and-openbsd-ftpd-bug-not-exploitable/&amp;title=FreeBSD+and+OpenBSD+ftpd+bug+%28not+exploitable%3F%29+&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22FreeBSD%20and%20OpenBSD%20ftpd%20bug%20%28not%20exploitable%3F%29%20%22&amp;body=Link: http://www.uncompiled.com/2010/03/freebsd-and-openbsd-ftpd-bug-not-exploitable/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/03/freebsd-and-openbsd-ftpd-bug-not-exploitable/&amp;t=FreeBSD+and+OpenBSD+ftpd+bug+%28not+exploitable%3F%29+" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/03/freebsd-and-openbsd-ftpd-bug-not-exploitable/&amp;title=FreeBSD+and+OpenBSD+ftpd+bug+%28not+exploitable%3F%29+&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/03/freebsd-and-openbsd-ftpd-bug-not-exploitable/&amp;title=FreeBSD+and+OpenBSD+ftpd+bug+%28not+exploitable%3F%29+" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/03/freebsd-and-openbsd-ftpd-bug-not-exploitable/&amp;title=FreeBSD+and+OpenBSD+ftpd+bug+%28not+exploitable%3F%29+" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/03/freebsd-and-openbsd-ftpd-bug-not-exploitable/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=FreeBSD+and+OpenBSD+ftpd+bug+%28not+exploitable%3F%29++-+http://b2l.me/jewp3&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/03/freebsd-and-openbsd-ftpd-bug-not-exploitable/&amp;submitHeadline=FreeBSD+and+OpenBSD+ftpd+bug+%28not+exploitable%3F%29+&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=FreeBSD+and+OpenBSD+ftpd+bug+%28not+exploitable%3F%29+&amp;body=Link: http://www.uncompiled.com/2010/03/freebsd-and-openbsd-ftpd-bug-not-exploitable/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/03/freebsd-and-openbsd-ftpd-bug-not-exploitable/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Password hole in GRUB boot loader closed</title>
		<link>http://www.uncompiled.com/2009/11/password-hole-in-grub-boot-loader-closed/</link>
		<comments>http://www.uncompiled.com/2009/11/password-hole-in-grub-boot-loader-closed/#comments</comments>
		<pubDate>Tue, 10 Nov 2009 14:34:34 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Bugs]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Open-Source]]></category>
		<category><![CDATA[Vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=352</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>The new version of the GNU GRUB boot loader, 1.97.1, closes a security hole in the previous version, 1.97, which allowed passwords be easily circumvented. The password protection is available in GRUB to prevent unauthorised modification of the boot parameters. A programming error in the feature lead to passwords being accepted as valid even if only the first character of the entered password was correct.</p>
<p>GRUB 1.97, also known as GRUB 2, has support for simple user authentication in its new config file format. The passwords do, though, need to be stored as readable clear text. Various Linux distributions are now being shipped with GRUB 2, including Debian &#8220;sid&#8221;, the soon to be released Fedora 12 and the recently released Ubuntu 9.10.</p>
<p><a href="http://www.h-online.com/security/news/item/Password-hole-in-GRUB-boot-loader-closed-855181.html">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2009/11/password-hole-in-grub-boot-loader-closed/&amp;n=Password+hole+in+GRUB+boot+loader+closed&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2009/11/password-hole-in-grub-boot-loader-closed/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2009/11/password-hole-in-grub-boot-loader-closed/&amp;title=Password+hole+in+GRUB+boot+loader+closed" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2009/11/password-hole-in-grub-boot-loader-closed/&amp;t=Password+hole+in+GRUB+boot+loader+closed" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2009/11/password-hole-in-grub-boot-loader-closed/&amp;title=Password+hole+in+GRUB+boot+loader+closed" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2009/11/password-hole-in-grub-boot-loader-closed/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2009/11/password-hole-in-grub-boot-loader-closed/&amp;title=Password+hole+in+GRUB+boot+loader+closed&amp;srcUrl=http://www.uncompiled.com/2009/11/password-hole-in-grub-boot-loader-closed/&amp;srcTitle=Password+hole+in+GRUB+boot+loader+closed&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2009/11/password-hole-in-grub-boot-loader-closed/&amp;title=Password+hole+in+GRUB+boot+loader+closed&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Password%20hole%20in%20GRUB%20boot%20loader%20closed%22&amp;body=Link: http://www.uncompiled.com/2009/11/password-hole-in-grub-boot-loader-closed/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2009/11/password-hole-in-grub-boot-loader-closed/&amp;t=Password+hole+in+GRUB+boot+loader+closed" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2009/11/password-hole-in-grub-boot-loader-closed/&amp;title=Password+hole+in+GRUB+boot+loader+closed&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2009/11/password-hole-in-grub-boot-loader-closed/&amp;title=Password+hole+in+GRUB+boot+loader+closed" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2009/11/password-hole-in-grub-boot-loader-closed/&amp;title=Password+hole+in+GRUB+boot+loader+closed" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2009/11/password-hole-in-grub-boot-loader-closed/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Password+hole+in+GRUB+boot+loader+closed+-+http://b2l.me/aak6d&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2009/11/password-hole-in-grub-boot-loader-closed/&amp;submitHeadline=Password+hole+in+GRUB+boot+loader+closed&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Password+hole+in+GRUB+boot+loader+closed&amp;body=Link: http://www.uncompiled.com/2009/11/password-hole-in-grub-boot-loader-closed/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2009/11/password-hole-in-grub-boot-loader-closed/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Linux 2.6.x fs/pipe.c local root exploit (CVE-2009-3547)</title>
		<link>http://www.uncompiled.com/2009/11/linux-2-6-x-fspipe-c-local-root-exploit-cve-2009-3547/</link>
		<comments>http://www.uncompiled.com/2009/11/linux-2-6-x-fspipe-c-local-root-exploit-cve-2009-3547/#comments</comments>
		<pubDate>Sun, 08 Nov 2009 14:29:33 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Bugs]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Kernel]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Open-Source]]></category>
		<category><![CDATA[Vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=328</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>For those who were not yet aware, there is at least 3 public exploits since 11/05/2009 for CVE-2009-3547 targeting *all* linux kernels from 2.6.0 to 2.6.31 included. Since spender and fotis have already release their own, there is not need for us to keep this on our hd. </p>
<p>ImpelDown.c is a poc trying to exploit null ptr dereference in fs/pipe.c for *all* linux kernel from 2.6.0 to 2.6.31 and ImpelDown-2.6.31only.c target only linux kernel version 2.6.31 (tested and approuved with mmap_min_addr at 0).</p>
<p>If you were writing your own, you have already noticed that there is a subtle difference in the way you can own kernels 2.6.0 up to 2.6.10 and kernels 2.6.11 up to 2.6.31: in the first one the null ptr deref leads to an arbitrary write to everywhere in the kernel since you have control over the destination address of </p>
<p>linux2.6.9/fs/pipe.c</p>
<p>&#8230;<br />
219                        if (pipe_iov_copy_from_user(pipebuf, iov, chars)) {<br />
&#8230;<br />
In such case, we try to exploit this by overwriting and old and obsolete syscall address in the sys_call_table by our privilege escalator function address (hehe old school trickz are always the best).</p>
<p>In kernels 2.6.11 up to 2.6.31, exploitation simply resume in mapping the correct struct pipe_inode_info at NULL and the kernel will call a fptr under our control at inode->i_pipe->bufs[1-16].ops->something()</p>
<p>You can find exploits at <a href="http://www.vxhell.org/~teach/exploits/ImpelDown.c">http://www.vxhell.org/~teach/exploits/ImpelDown.c</a> and <a href="http://www.vxhell.org/~teach/exploits/ImpelDown-2.6.31only.c">http://www.vxhell.org/~teach/exploits/ImpelDown-2.6.31only.c</a>. The first one wasn&#8217;t tested but the second would work for the given kernel  (according to your mmap_min_addr)</p>
<p><a href="http://seclists.org/fulldisclosure/2009/Nov/105">Source</a></p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2009/11/linux-2-6-x-fspipe-c-local-root-exploit-cve-2009-3547/&amp;n=Linux+2.6.x+fs%2Fpipe.c+local+root+exploit+%28CVE-2009-3547%29&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2009/11/linux-2-6-x-fspipe-c-local-root-exploit-cve-2009-3547/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2009/11/linux-2-6-x-fspipe-c-local-root-exploit-cve-2009-3547/&amp;title=Linux+2.6.x+fs%2Fpipe.c+local+root+exploit+%28CVE-2009-3547%29" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2009/11/linux-2-6-x-fspipe-c-local-root-exploit-cve-2009-3547/&amp;t=Linux+2.6.x+fs%2Fpipe.c+local+root+exploit+%28CVE-2009-3547%29" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2009/11/linux-2-6-x-fspipe-c-local-root-exploit-cve-2009-3547/&amp;title=Linux+2.6.x+fs%2Fpipe.c+local+root+exploit+%28CVE-2009-3547%29" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2009/11/linux-2-6-x-fspipe-c-local-root-exploit-cve-2009-3547/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2009/11/linux-2-6-x-fspipe-c-local-root-exploit-cve-2009-3547/&amp;title=Linux+2.6.x+fs%2Fpipe.c+local+root+exploit+%28CVE-2009-3547%29&amp;srcUrl=http://www.uncompiled.com/2009/11/linux-2-6-x-fspipe-c-local-root-exploit-cve-2009-3547/&amp;srcTitle=Linux+2.6.x+fs%2Fpipe.c+local+root+exploit+%28CVE-2009-3547%29&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2009/11/linux-2-6-x-fspipe-c-local-root-exploit-cve-2009-3547/&amp;title=Linux+2.6.x+fs%2Fpipe.c+local+root+exploit+%28CVE-2009-3547%29&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Linux%202.6.x%20fs%2Fpipe.c%20local%20root%20exploit%20%28CVE-2009-3547%29%22&amp;body=Link: http://www.uncompiled.com/2009/11/linux-2-6-x-fspipe-c-local-root-exploit-cve-2009-3547/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2009/11/linux-2-6-x-fspipe-c-local-root-exploit-cve-2009-3547/&amp;t=Linux+2.6.x+fs%2Fpipe.c+local+root+exploit+%28CVE-2009-3547%29" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2009/11/linux-2-6-x-fspipe-c-local-root-exploit-cve-2009-3547/&amp;title=Linux+2.6.x+fs%2Fpipe.c+local+root+exploit+%28CVE-2009-3547%29&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2009/11/linux-2-6-x-fspipe-c-local-root-exploit-cve-2009-3547/&amp;title=Linux+2.6.x+fs%2Fpipe.c+local+root+exploit+%28CVE-2009-3547%29" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2009/11/linux-2-6-x-fspipe-c-local-root-exploit-cve-2009-3547/&amp;title=Linux+2.6.x+fs%2Fpipe.c+local+root+exploit+%28CVE-2009-3547%29" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2009/11/linux-2-6-x-fspipe-c-local-root-exploit-cve-2009-3547/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Linux+2.6.x+fs%2Fpipe.c+local+root+exploit+%28CVE-2009-3547%29+-+http://b2l.me/8rkj&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2009/11/linux-2-6-x-fspipe-c-local-root-exploit-cve-2009-3547/&amp;submitHeadline=Linux+2.6.x+fs%2Fpipe.c+local+root+exploit+%28CVE-2009-3547%29&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Linux+2.6.x+fs%2Fpipe.c+local+root+exploit+%28CVE-2009-3547%29&amp;body=Link: http://www.uncompiled.com/2009/11/linux-2-6-x-fspipe-c-local-root-exploit-cve-2009-3547/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2009/11/linux-2-6-x-fspipe-c-local-root-exploit-cve-2009-3547/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Brad Spengler Releases MooseCox</title>
		<link>http://www.uncompiled.com/2009/11/brad-spengler-releases-moosecox/</link>
		<comments>http://www.uncompiled.com/2009/11/brad-spengler-releases-moosecox/#comments</comments>
		<pubDate>Thu, 05 Nov 2009 00:50:00 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Bugs]]></category>
		<category><![CDATA[Kernel]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=302</guid>
		<description><![CDATA[From Brad Spengler&#8217;s Twitter MooseCox released in enlightenment: http://bit.ly/dEtOG complete with OpenBSD history lesson and a picture in the post-exploit payload This was referenced earlier in Bug in latest Linux gives untrusted users root access Blog this on Blogger Subscribe to the comments for this post? Digg this! Share this on Facebook Add this to [...]]]></description>
			<content:encoded><![CDATA[<p>From <a href="http://twitter.com/spendergrsec">Brad Spengler&#8217;s Twitter</a></p>
<blockquote><p>
MooseCox released in enlightenment: http://bit.ly/dEtOG complete with OpenBSD history lesson and a picture in the post-exploit payload
</p></blockquote>
<p>This was referenced earlier in <a href="http://www.uncompiled.com/2009/11/bug-in-latest-linux-gives-untrusted-users-root-access/">Bug in latest Linux gives untrusted users root access</a></p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2009/11/brad-spengler-releases-moosecox/&amp;n=Brad+Spengler+Releases+MooseCox&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2009/11/brad-spengler-releases-moosecox/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2009/11/brad-spengler-releases-moosecox/&amp;title=Brad+Spengler+Releases+MooseCox" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2009/11/brad-spengler-releases-moosecox/&amp;t=Brad+Spengler+Releases+MooseCox" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2009/11/brad-spengler-releases-moosecox/&amp;title=Brad+Spengler+Releases+MooseCox" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2009/11/brad-spengler-releases-moosecox/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2009/11/brad-spengler-releases-moosecox/&amp;title=Brad+Spengler+Releases+MooseCox&amp;srcUrl=http://www.uncompiled.com/2009/11/brad-spengler-releases-moosecox/&amp;srcTitle=Brad+Spengler+Releases+MooseCox&amp;snippet=From%20Brad%20Spengler%27s%20Twitter%0D%0A%0D%0A%0D%0AMooseCox%20released%20in%20enlightenment%3A%20http%3A%2F%2Fbit.ly%2FdEtOG%20complete%20with%20OpenBSD%20history%20lesson%20and%20a%20picture%20in%20the%20post-exploit%20payload%0D%0A%0D%0A%0D%0AThis%20was%20referenced%20earlier%20in%20Bug%20in%20latest%20Linux%20gives%20untrusted%20users%20root%20access" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2009/11/brad-spengler-releases-moosecox/&amp;title=Brad+Spengler+Releases+MooseCox&amp;summary=From%20Brad%20Spengler%27s%20Twitter%0D%0A%0D%0A%0D%0AMooseCox%20released%20in%20enlightenment%3A%20http%3A%2F%2Fbit.ly%2FdEtOG%20complete%20with%20OpenBSD%20history%20lesson%20and%20a%20picture%20in%20the%20post-exploit%20payload%0D%0A%0D%0A%0D%0AThis%20was%20referenced%20earlier%20in%20Bug%20in%20latest%20Linux%20gives%20untrusted%20users%20root%20access&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Brad%20Spengler%20Releases%20MooseCox%22&amp;body=Link: http://www.uncompiled.com/2009/11/brad-spengler-releases-moosecox/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A From%20Brad%20Spengler%27s%20Twitter%0D%0A%0D%0A%0D%0AMooseCox%20released%20in%20enlightenment%3A%20http%3A%2F%2Fbit.ly%2FdEtOG%20complete%20with%20OpenBSD%20history%20lesson%20and%20a%20picture%20in%20the%20post-exploit%20payload%0D%0A%0D%0A%0D%0AThis%20was%20referenced%20earlier%20in%20Bug%20in%20latest%20Linux%20gives%20untrusted%20users%20root%20access" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2009/11/brad-spengler-releases-moosecox/&amp;t=Brad+Spengler+Releases+MooseCox" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2009/11/brad-spengler-releases-moosecox/&amp;title=Brad+Spengler+Releases+MooseCox&amp;body=From%20Brad%20Spengler%27s%20Twitter%0D%0A%0D%0A%0D%0AMooseCox%20released%20in%20enlightenment%3A%20http%3A%2F%2Fbit.ly%2FdEtOG%20complete%20with%20OpenBSD%20history%20lesson%20and%20a%20picture%20in%20the%20post-exploit%20payload%0D%0A%0D%0A%0D%0AThis%20was%20referenced%20earlier%20in%20Bug%20in%20latest%20Linux%20gives%20untrusted%20users%20root%20access" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2009/11/brad-spengler-releases-moosecox/&amp;title=Brad+Spengler+Releases+MooseCox" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2009/11/brad-spengler-releases-moosecox/&amp;title=Brad+Spengler+Releases+MooseCox" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2009/11/brad-spengler-releases-moosecox/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Brad+Spengler+Releases+MooseCox+-+http://b2l.me/5gef&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2009/11/brad-spengler-releases-moosecox/&amp;submitHeadline=Brad+Spengler+Releases+MooseCox&amp;submitSummary=From%20Brad%20Spengler%27s%20Twitter%0D%0A%0D%0A%0D%0AMooseCox%20released%20in%20enlightenment%3A%20http%3A%2F%2Fbit.ly%2FdEtOG%20complete%20with%20OpenBSD%20history%20lesson%20and%20a%20picture%20in%20the%20post-exploit%20payload%0D%0A%0D%0A%0D%0AThis%20was%20referenced%20earlier%20in%20Bug%20in%20latest%20Linux%20gives%20untrusted%20users%20root%20access&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Brad+Spengler+Releases+MooseCox&amp;body=Link: http://www.uncompiled.com/2009/11/brad-spengler-releases-moosecox/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A From%20Brad%20Spengler%27s%20Twitter%0D%0A%0D%0A%0D%0AMooseCox%20released%20in%20enlightenment%3A%20http%3A%2F%2Fbit.ly%2FdEtOG%20complete%20with%20OpenBSD%20history%20lesson%20and%20a%20picture%20in%20the%20post-exploit%20payload%0D%0A%0D%0A%0D%0AThis%20was%20referenced%20earlier%20in%20Bug%20in%20latest%20Linux%20gives%20untrusted%20users%20root%20access" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2009/11/brad-spengler-releases-moosecox/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bug in latest Linux gives untrusted users root access</title>
		<link>http://www.uncompiled.com/2009/11/bug-in-latest-linux-gives-untrusted-users-root-access/</link>
		<comments>http://www.uncompiled.com/2009/11/bug-in-latest-linux-gives-untrusted-users-root-access/#comments</comments>
		<pubDate>Tue, 03 Nov 2009 21:08:35 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Bugs]]></category>
		<category><![CDATA[Kernel]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=274</guid>
		<description><![CDATA[A software developer has uncovered a bug in most versions of Linux that could allow untrusted users to gain complete control over the open-source operating system. The null pointer dereference flaw was only fixed in the upcoming 2.6.32 release candidate of the Linux kernel, making virtually all production versions in use at the moment vulnerable. [...]]]></description>
			<content:encoded><![CDATA[<p>A software developer has uncovered a bug in most versions of Linux that could allow untrusted users to gain complete control over the open-source operating system.</p>
<p>The null pointer dereference flaw was only fixed in the upcoming 2.6.32 release candidate of the Linux kernel, making virtually all production versions in use at the moment vulnerable. While attacks can be prevented by implementing a common feature known as mmap_min_addr, the RHEL distribution, short for Red Hat Enterprise Linux, doesn&#8217;t properly implement that protection, Brad Spengler, who discovered the bug in mid October, told The Register.</p>
<p><a href="http://www.theregister.co.uk/2009/11/03/linux_kernel_vulnerability/">Source</a></p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2009/11/bug-in-latest-linux-gives-untrusted-users-root-access/&amp;n=Bug+in+latest+Linux+gives+untrusted+users+root+access&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2009/11/bug-in-latest-linux-gives-untrusted-users-root-access/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2009/11/bug-in-latest-linux-gives-untrusted-users-root-access/&amp;title=Bug+in+latest+Linux+gives+untrusted+users+root+access" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2009/11/bug-in-latest-linux-gives-untrusted-users-root-access/&amp;t=Bug+in+latest+Linux+gives+untrusted+users+root+access" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2009/11/bug-in-latest-linux-gives-untrusted-users-root-access/&amp;title=Bug+in+latest+Linux+gives+untrusted+users+root+access" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2009/11/bug-in-latest-linux-gives-untrusted-users-root-access/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2009/11/bug-in-latest-linux-gives-untrusted-users-root-access/&amp;title=Bug+in+latest+Linux+gives+untrusted+users+root+access&amp;srcUrl=http://www.uncompiled.com/2009/11/bug-in-latest-linux-gives-untrusted-users-root-access/&amp;srcTitle=Bug+in+latest+Linux+gives+untrusted+users+root+access&amp;snippet=A%20software%20developer%20has%20uncovered%20a%20bug%20in%20most%20versions%20of%20Linux%20that%20could%20allow%20untrusted%20users%20to%20gain%20complete%20control%20over%20the%20open-source%20operating%20system.%0D%0A%0D%0AThe%20null%20pointer%20dereference%20flaw%20was%20only%20fixed%20in%20the%20upcoming%202.6.32%20release%20candidate%20of%20the%20Linux%20kernel%2C%20making%20virtually%20all%20p" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2009/11/bug-in-latest-linux-gives-untrusted-users-root-access/&amp;title=Bug+in+latest+Linux+gives+untrusted+users+root+access&amp;summary=A%20software%20developer%20has%20uncovered%20a%20bug%20in%20most%20versions%20of%20Linux%20that%20could%20allow%20untrusted%20users%20to%20gain%20complete%20control%20over%20the%20open-source%20operating%20system.%0D%0A%0D%0AThe%20null%20pointer%20dereference%20flaw%20was%20only%20fixed%20in%20the%20upcoming%202.6.32%20release%20candidate%20of%20the%20Linux%20kernel%2C%20making%20virtually%20all%20p&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Bug%20in%20latest%20Linux%20gives%20untrusted%20users%20root%20access%22&amp;body=Link: http://www.uncompiled.com/2009/11/bug-in-latest-linux-gives-untrusted-users-root-access/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A A%20software%20developer%20has%20uncovered%20a%20bug%20in%20most%20versions%20of%20Linux%20that%20could%20allow%20untrusted%20users%20to%20gain%20complete%20control%20over%20the%20open-source%20operating%20system.%0D%0A%0D%0AThe%20null%20pointer%20dereference%20flaw%20was%20only%20fixed%20in%20the%20upcoming%202.6.32%20release%20candidate%20of%20the%20Linux%20kernel%2C%20making%20virtually%20all%20p" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2009/11/bug-in-latest-linux-gives-untrusted-users-root-access/&amp;t=Bug+in+latest+Linux+gives+untrusted+users+root+access" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2009/11/bug-in-latest-linux-gives-untrusted-users-root-access/&amp;title=Bug+in+latest+Linux+gives+untrusted+users+root+access&amp;body=A%20software%20developer%20has%20uncovered%20a%20bug%20in%20most%20versions%20of%20Linux%20that%20could%20allow%20untrusted%20users%20to%20gain%20complete%20control%20over%20the%20open-source%20operating%20system.%0D%0A%0D%0AThe%20null%20pointer%20dereference%20flaw%20was%20only%20fixed%20in%20the%20upcoming%202.6.32%20release%20candidate%20of%20the%20Linux%20kernel%2C%20making%20virtually%20all%20p" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2009/11/bug-in-latest-linux-gives-untrusted-users-root-access/&amp;title=Bug+in+latest+Linux+gives+untrusted+users+root+access" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2009/11/bug-in-latest-linux-gives-untrusted-users-root-access/&amp;title=Bug+in+latest+Linux+gives+untrusted+users+root+access" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2009/11/bug-in-latest-linux-gives-untrusted-users-root-access/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Bug+in+latest+Linux+gives+untrusted+users+root+access+-+http://b2l.me/4hby&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2009/11/bug-in-latest-linux-gives-untrusted-users-root-access/&amp;submitHeadline=Bug+in+latest+Linux+gives+untrusted+users+root+access&amp;submitSummary=A%20software%20developer%20has%20uncovered%20a%20bug%20in%20most%20versions%20of%20Linux%20that%20could%20allow%20untrusted%20users%20to%20gain%20complete%20control%20over%20the%20open-source%20operating%20system.%0D%0A%0D%0AThe%20null%20pointer%20dereference%20flaw%20was%20only%20fixed%20in%20the%20upcoming%202.6.32%20release%20candidate%20of%20the%20Linux%20kernel%2C%20making%20virtually%20all%20p&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Bug+in+latest+Linux+gives+untrusted+users+root+access&amp;body=Link: http://www.uncompiled.com/2009/11/bug-in-latest-linux-gives-untrusted-users-root-access/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A A%20software%20developer%20has%20uncovered%20a%20bug%20in%20most%20versions%20of%20Linux%20that%20could%20allow%20untrusted%20users%20to%20gain%20complete%20control%20over%20the%20open-source%20operating%20system.%0D%0A%0D%0AThe%20null%20pointer%20dereference%20flaw%20was%20only%20fixed%20in%20the%20upcoming%202.6.32%20release%20candidate%20of%20the%20Linux%20kernel%2C%20making%20virtually%20all%20p" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2009/11/bug-in-latest-linux-gives-untrusted-users-root-access/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Multiple BSD printf(1) and multiple dtoa/*printf(3) vulnerabilities</title>
		<link>http://www.uncompiled.com/2009/10/multiple-bsd-printf1-and-multiple-dtoaprintf3-vulnerabilities/</link>
		<comments>http://www.uncompiled.com/2009/10/multiple-bsd-printf1-and-multiple-dtoaprintf3-vulnerabilities/#comments</comments>
		<pubDate>Fri, 30 Oct 2009 20:41:11 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[BSD]]></category>
		<category><![CDATA[Bugs]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=222</guid>
		<description><![CDATA[printf(1) formats and prints its arguments, after the first, under control of the format. The format is a character string which contains three types of objects: plain characters, which are simply copied to standard output, character escape sequences which are converted and copied to the standard output, and format specifications, each of which causes printing [...]]]></description>
			<content:encoded><![CDATA[<p>printf(1) formats and prints its arguments, after the first, under control of the format.  The format is a character string which contains three types of objects: plain characters, which are simply copied to standard output, character escape sequences which are converted and copied to the standard output, and format specifications, each of which causes printing of the next successive argument.</p>
<p><a href="http://securityreason.com/achievement_securityalert/69">Source</a></p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2009/10/multiple-bsd-printf1-and-multiple-dtoaprintf3-vulnerabilities/&amp;n=Multiple+BSD+printf%281%29+and+multiple+dtoa%2F%2Aprintf%283%29+vulnerabilities&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2009/10/multiple-bsd-printf1-and-multiple-dtoaprintf3-vulnerabilities/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2009/10/multiple-bsd-printf1-and-multiple-dtoaprintf3-vulnerabilities/&amp;title=Multiple+BSD+printf%281%29+and+multiple+dtoa%2F%2Aprintf%283%29+vulnerabilities" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2009/10/multiple-bsd-printf1-and-multiple-dtoaprintf3-vulnerabilities/&amp;t=Multiple+BSD+printf%281%29+and+multiple+dtoa%2F%2Aprintf%283%29+vulnerabilities" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2009/10/multiple-bsd-printf1-and-multiple-dtoaprintf3-vulnerabilities/&amp;title=Multiple+BSD+printf%281%29+and+multiple+dtoa%2F%2Aprintf%283%29+vulnerabilities" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2009/10/multiple-bsd-printf1-and-multiple-dtoaprintf3-vulnerabilities/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2009/10/multiple-bsd-printf1-and-multiple-dtoaprintf3-vulnerabilities/&amp;title=Multiple+BSD+printf%281%29+and+multiple+dtoa%2F%2Aprintf%283%29+vulnerabilities&amp;srcUrl=http://www.uncompiled.com/2009/10/multiple-bsd-printf1-and-multiple-dtoaprintf3-vulnerabilities/&amp;srcTitle=Multiple+BSD+printf%281%29+and+multiple+dtoa%2F%2Aprintf%283%29+vulnerabilities&amp;snippet=printf%281%29%20formats%20and%20prints%20its%20arguments%2C%20after%20the%20first%2C%20under%20control%20of%20the%20format.%20%20The%20format%20is%20a%20character%20string%20which%20contains%20three%20types%20of%20objects%3A%20plain%20characters%2C%20which%20are%20simply%20copied%20to%20standard%20output%2C%20character%20escape%20sequences%20which%20are%20converted%20and%20copied%20to%20the%20standard%20o" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2009/10/multiple-bsd-printf1-and-multiple-dtoaprintf3-vulnerabilities/&amp;title=Multiple+BSD+printf%281%29+and+multiple+dtoa%2F%2Aprintf%283%29+vulnerabilities&amp;summary=printf%281%29%20formats%20and%20prints%20its%20arguments%2C%20after%20the%20first%2C%20under%20control%20of%20the%20format.%20%20The%20format%20is%20a%20character%20string%20which%20contains%20three%20types%20of%20objects%3A%20plain%20characters%2C%20which%20are%20simply%20copied%20to%20standard%20output%2C%20character%20escape%20sequences%20which%20are%20converted%20and%20copied%20to%20the%20standard%20o&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Multiple%20BSD%20printf%281%29%20and%20multiple%20dtoa%2F%2Aprintf%283%29%20vulnerabilities%22&amp;body=Link: http://www.uncompiled.com/2009/10/multiple-bsd-printf1-and-multiple-dtoaprintf3-vulnerabilities/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A printf%281%29%20formats%20and%20prints%20its%20arguments%2C%20after%20the%20first%2C%20under%20control%20of%20the%20format.%20%20The%20format%20is%20a%20character%20string%20which%20contains%20three%20types%20of%20objects%3A%20plain%20characters%2C%20which%20are%20simply%20copied%20to%20standard%20output%2C%20character%20escape%20sequences%20which%20are%20converted%20and%20copied%20to%20the%20standard%20o" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2009/10/multiple-bsd-printf1-and-multiple-dtoaprintf3-vulnerabilities/&amp;t=Multiple+BSD+printf%281%29+and+multiple+dtoa%2F%2Aprintf%283%29+vulnerabilities" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2009/10/multiple-bsd-printf1-and-multiple-dtoaprintf3-vulnerabilities/&amp;title=Multiple+BSD+printf%281%29+and+multiple+dtoa%2F%2Aprintf%283%29+vulnerabilities&amp;body=printf%281%29%20formats%20and%20prints%20its%20arguments%2C%20after%20the%20first%2C%20under%20control%20of%20the%20format.%20%20The%20format%20is%20a%20character%20string%20which%20contains%20three%20types%20of%20objects%3A%20plain%20characters%2C%20which%20are%20simply%20copied%20to%20standard%20output%2C%20character%20escape%20sequences%20which%20are%20converted%20and%20copied%20to%20the%20standard%20o" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2009/10/multiple-bsd-printf1-and-multiple-dtoaprintf3-vulnerabilities/&amp;title=Multiple+BSD+printf%281%29+and+multiple+dtoa%2F%2Aprintf%283%29+vulnerabilities" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2009/10/multiple-bsd-printf1-and-multiple-dtoaprintf3-vulnerabilities/&amp;title=Multiple+BSD+printf%281%29+and+multiple+dtoa%2F%2Aprintf%283%29+vulnerabilities" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2009/10/multiple-bsd-printf1-and-multiple-dtoaprintf3-vulnerabilities/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Multiple+BSD+printf%281%29+and+multiple+dtoa%2F%2Aprintf%283%29+vulnerabilities+-+http://b2l.me/zk2w&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2009/10/multiple-bsd-printf1-and-multiple-dtoaprintf3-vulnerabilities/&amp;submitHeadline=Multiple+BSD+printf%281%29+and+multiple+dtoa%2F%2Aprintf%283%29+vulnerabilities&amp;submitSummary=printf%281%29%20formats%20and%20prints%20its%20arguments%2C%20after%20the%20first%2C%20under%20control%20of%20the%20format.%20%20The%20format%20is%20a%20character%20string%20which%20contains%20three%20types%20of%20objects%3A%20plain%20characters%2C%20which%20are%20simply%20copied%20to%20standard%20output%2C%20character%20escape%20sequences%20which%20are%20converted%20and%20copied%20to%20the%20standard%20o&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Multiple+BSD+printf%281%29+and+multiple+dtoa%2F%2Aprintf%283%29+vulnerabilities&amp;body=Link: http://www.uncompiled.com/2009/10/multiple-bsd-printf1-and-multiple-dtoaprintf3-vulnerabilities/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A printf%281%29%20formats%20and%20prints%20its%20arguments%2C%20after%20the%20first%2C%20under%20control%20of%20the%20format.%20%20The%20format%20is%20a%20character%20string%20which%20contains%20three%20types%20of%20objects%3A%20plain%20characters%2C%20which%20are%20simply%20copied%20to%20standard%20output%2C%20character%20escape%20sequences%20which%20are%20converted%20and%20copied%20to%20the%20standard%20o" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2009/10/multiple-bsd-printf1-and-multiple-dtoaprintf3-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Debian Unstable (Sid) &#8211; Unable to Change Root Password</title>
		<link>http://www.uncompiled.com/2009/10/debian-unstable-sid-unable-to-change-root-password/</link>
		<comments>http://www.uncompiled.com/2009/10/debian-unstable-sid-unable-to-change-root-password/#comments</comments>
		<pubDate>Thu, 29 Oct 2009 00:28:33 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Bugs]]></category>
		<category><![CDATA[Debian]]></category>
		<category><![CDATA[Linux]]></category>

		<guid isPermaLink="false">http://localhost/?p=90</guid>
		<description><![CDATA[Today while updating the server that uncompiled.com runs on, I ran into a weird problem that is a first for me using Debian. After changing my APT sources from Lenny to Sid and doing a routine apt-get dist-upgrade, I by necessity went to change my root password. Normally a very mundane task for a Linux [...]]]></description>
			<content:encoded><![CDATA[<p>Today while updating the server that <a title="uncompiled.com" href="http://www.uncompiled.com" target="_self">uncompiled.com</a> runs on, I ran into a weird problem that is a first for me using Debian. After changing my APT sources from Lenny to Sid and doing a routine <em>apt-get dist-upgrade</em>, I by necessity went to change my root password. Normally a very mundane task for a Linux system, I immediately hit a wall.</p>
<blockquote><p>www:~# passwd root<br />
passwd: Authentication token manipulation error<br />
passwd: password unchanged</p></blockquote>
<p>Upon seeing this, I started to figure out reasons why this may occur. After attempting to double-check <em>/etc/passwd</em> &amp; <em>/etc/shadow</em> for any anomolies, I moved on to a recommendation by a friend who told me to try a <em>pwconv</em> just in case files had gotten out of sync. Nothing was panning out for a solution. I decided to test a normal user account which presented me with an interesting situation.</p>
<blockquote><p>www:~# passwd test<br />
Current Kerberos password:</p></blockquote>
<p>Here&#8217;s the problem &#8212; I don&#8217;t use Kerberos on this system, nor did I even have the software installed to begin with on the system. Having noted this, I edited <em>/etc/pam.d/common-password</em> and noticed immediately that an undesired line was present</p>
<blockquote><p>password        requisite                       pam_krb5.so minimum_uid=1000</p></blockquote>
<p>I went ahead and decided to just completely purge the problem considering that again, I had no use for Kerberos authentication with PAM on my system. I opted to execute the following command.</p>
<blockquote><p># apt-get remove &#8211;purge libpam-krb5</p></blockquote>
<p>Once executed, password changing resumed to functioning properly.</p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2009/10/debian-unstable-sid-unable-to-change-root-password/&amp;n=Debian+Unstable+%28Sid%29+-+Unable+to+Change+Root+Password&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2009/10/debian-unstable-sid-unable-to-change-root-password/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2009/10/debian-unstable-sid-unable-to-change-root-password/&amp;title=Debian+Unstable+%28Sid%29+-+Unable+to+Change+Root+Password" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2009/10/debian-unstable-sid-unable-to-change-root-password/&amp;t=Debian+Unstable+%28Sid%29+-+Unable+to+Change+Root+Password" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2009/10/debian-unstable-sid-unable-to-change-root-password/&amp;title=Debian+Unstable+%28Sid%29+-+Unable+to+Change+Root+Password" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2009/10/debian-unstable-sid-unable-to-change-root-password/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2009/10/debian-unstable-sid-unable-to-change-root-password/&amp;title=Debian+Unstable+%28Sid%29+-+Unable+to+Change+Root+Password&amp;srcUrl=http://www.uncompiled.com/2009/10/debian-unstable-sid-unable-to-change-root-password/&amp;srcTitle=Debian+Unstable+%28Sid%29+-+Unable+to+Change+Root+Password&amp;snippet=Today%20while%20updating%20the%20server%20that%20uncompiled.com%20runs%20on%2C%20I%20ran%20into%20a%20weird%20problem%20that%20is%20a%20first%20for%20me%20using%20Debian.%20After%20changing%20my%20APT%20sources%20from%20Lenny%20to%20Sid%20and%20doing%20a%20routine%20apt-get%20dist-upgrade%2C%20I%20by%20necessity%20went%20to%20change%20my%20root%20password.%20Normally%20a%20very%20mundane%20task%20for%20a%20Li" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2009/10/debian-unstable-sid-unable-to-change-root-password/&amp;title=Debian+Unstable+%28Sid%29+-+Unable+to+Change+Root+Password&amp;summary=Today%20while%20updating%20the%20server%20that%20uncompiled.com%20runs%20on%2C%20I%20ran%20into%20a%20weird%20problem%20that%20is%20a%20first%20for%20me%20using%20Debian.%20After%20changing%20my%20APT%20sources%20from%20Lenny%20to%20Sid%20and%20doing%20a%20routine%20apt-get%20dist-upgrade%2C%20I%20by%20necessity%20went%20to%20change%20my%20root%20password.%20Normally%20a%20very%20mundane%20task%20for%20a%20Li&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Debian%20Unstable%20%28Sid%29%20-%20Unable%20to%20Change%20Root%20Password%22&amp;body=Link: http://www.uncompiled.com/2009/10/debian-unstable-sid-unable-to-change-root-password/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A Today%20while%20updating%20the%20server%20that%20uncompiled.com%20runs%20on%2C%20I%20ran%20into%20a%20weird%20problem%20that%20is%20a%20first%20for%20me%20using%20Debian.%20After%20changing%20my%20APT%20sources%20from%20Lenny%20to%20Sid%20and%20doing%20a%20routine%20apt-get%20dist-upgrade%2C%20I%20by%20necessity%20went%20to%20change%20my%20root%20password.%20Normally%20a%20very%20mundane%20task%20for%20a%20Li" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2009/10/debian-unstable-sid-unable-to-change-root-password/&amp;t=Debian+Unstable+%28Sid%29+-+Unable+to+Change+Root+Password" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2009/10/debian-unstable-sid-unable-to-change-root-password/&amp;title=Debian+Unstable+%28Sid%29+-+Unable+to+Change+Root+Password&amp;body=Today%20while%20updating%20the%20server%20that%20uncompiled.com%20runs%20on%2C%20I%20ran%20into%20a%20weird%20problem%20that%20is%20a%20first%20for%20me%20using%20Debian.%20After%20changing%20my%20APT%20sources%20from%20Lenny%20to%20Sid%20and%20doing%20a%20routine%20apt-get%20dist-upgrade%2C%20I%20by%20necessity%20went%20to%20change%20my%20root%20password.%20Normally%20a%20very%20mundane%20task%20for%20a%20Li" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2009/10/debian-unstable-sid-unable-to-change-root-password/&amp;title=Debian+Unstable+%28Sid%29+-+Unable+to+Change+Root+Password" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2009/10/debian-unstable-sid-unable-to-change-root-password/&amp;title=Debian+Unstable+%28Sid%29+-+Unable+to+Change+Root+Password" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2009/10/debian-unstable-sid-unable-to-change-root-password/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Debian+Unstable+%28Sid%29+-+Unable+to+Change+Root+Password+-+http://b2l.me/yecg&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2009/10/debian-unstable-sid-unable-to-change-root-password/&amp;submitHeadline=Debian+Unstable+%28Sid%29+-+Unable+to+Change+Root+Password&amp;submitSummary=Today%20while%20updating%20the%20server%20that%20uncompiled.com%20runs%20on%2C%20I%20ran%20into%20a%20weird%20problem%20that%20is%20a%20first%20for%20me%20using%20Debian.%20After%20changing%20my%20APT%20sources%20from%20Lenny%20to%20Sid%20and%20doing%20a%20routine%20apt-get%20dist-upgrade%2C%20I%20by%20necessity%20went%20to%20change%20my%20root%20password.%20Normally%20a%20very%20mundane%20task%20for%20a%20Li&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Debian+Unstable+%28Sid%29+-+Unable+to+Change+Root+Password&amp;body=Link: http://www.uncompiled.com/2009/10/debian-unstable-sid-unable-to-change-root-password/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A Today%20while%20updating%20the%20server%20that%20uncompiled.com%20runs%20on%2C%20I%20ran%20into%20a%20weird%20problem%20that%20is%20a%20first%20for%20me%20using%20Debian.%20After%20changing%20my%20APT%20sources%20from%20Lenny%20to%20Sid%20and%20doing%20a%20routine%20apt-get%20dist-upgrade%2C%20I%20by%20necessity%20went%20to%20change%20my%20root%20password.%20Normally%20a%20very%20mundane%20task%20for%20a%20Li" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2009/10/debian-unstable-sid-unable-to-change-root-password/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
