ISS Internet Scanner Brute Force Bug

From: alexander tampermeier (alex_tampermeierat_private)
Date: Wed Feb 17 1999 - 23:54:11 PST

  • Next message: Alan Cox: "Re: xtvscreen and suse 6"

    The Internet Scanner lets you brute force by using username/password
    pairs specified in the file default.login. I specified a known
    username/password pair but the scanner could not login.
    The reason is that the Internet Scanner needs a carriage return after
    the last username/password pair. If it finds just an EOF marker then the
    password gets modified by adding an additional character.
    For example the password test is modified to testo.
    Get Your Private, Free Email at

    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 14:35:29 PDT