Re: lynx - someone is deaf and blind ;)

From: Mariusz Woloszyn (emsiat_private)
Date: Tue Mar 07 2000 - 10:01:30 PST

  • Next message: Bram Kerkhof: "NAI/McAfee Viruscan Engine does not scan .VBS files by default"

    On Sat, 4 Mar 2000, Kris Kennaway wrote:
    
    > > extremely long URLs. I'm not going to give more examples here, as I'm
    > > afraid I might miss one or two that won't be fixed - developers, use your
    > > head, take a look at the code and fix every suspected piece of code, not
    > > only already published / described bugs.
    > 
    > I have just disabled the lynx port/package in FreeBSD. We won't be
    > shipping it in FreeBSD 4.0, or until this gets addressed. It's a shame
    > because it's such a popular and useful tool, but the risk to users is just
    > too great.
    > 
    > Thanks for notifying the world of these problems :)
    > 
    I was trying to exploit lynx bug several times.
    It's true that lynx segfaults on long URLs, but exploiting it is (IMHO)
    impossible because lynx strips all nonprintable characters thus smugling
    RET address is impossible. I have never heard about ASCII only shellcode
    also :)
    I assume lynx bugs are unexploitable...
    
    P.S. You can compile lynx using StackGuard also (AFAIK only under Linux).
    
    --
    Mariusz Wołoszyn
    Internet Security Specialist, Internet Partners, GTS Poland
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 15:39:07 PDT