Re: MSN666 "backdoor"

From: Seunghyun Seo (s1980914at_private)
Date: Fri Jun 14 2002 - 09:04:53 PDT

  • Next message: sec: "Another cgiemail bug"

    yeh, dude 
    
    MSN666 has no backdoors , but gobble confused, he even wrote *alert mail ,
    he seems to be very nervous against MSN666
    
    actually , it has some bugs ,
    coz of it is the proof of concept code for "Sensitive IM Security"
    
    i don't think ppls use this as a Server like apache or mysql.
    hehe
    
    
    --
    Seunghyun Seo , Inha university Group of Research for Unix Security
    [e-mail] seoat_private, seoat_private
    ----- Original Message ----- 
    
    > 
    > I don't beleive that MSN666 has a backdoor. Is the function pattern2 safe
    > in it's use of sscanf? What if msg = "XXXXXXXXXXXXXXXXXAAAABBBB" is longer
    > than 16 bytes on line 254?
    > 
    > sscanf ( msg, "%s", &opmsg )
    > 
    > Any help is appreciated.
    > 
    > Keith Rogers
    > SecurityFocus
    > www.securityfocus.com
    > 
    > 
    



    This archive was generated by hypermail 2b30 : Fri Jun 14 2002 - 09:43:27 PDT