Re: possible 0-day exploit for latest Real-/Helixserver 9.0.2.794

From: Juri Haberland (juriat_private)
Date: Wed Aug 20 2003 - 03:39:03 PDT

  • Next message: Alexander Reelsen: "Re: possible 0-day exploit for latest Real-/Helixserver 9.0.2.794"

    Brian Benitez wrote:
    
    > can anyone confirm if this exploit would work on a FreeBSD Helix 
    > server? We have been having unexplained spontaneous restarts 
    > for a while now, but as of August 17th they've been accompanied 
    > by the behavior of not writing the access log after the restart.
    > 
    > We're running 9.0.2.794 on FreeBSD 4.8. 
    > 
    > We haven't found any obvious rootkit signs, but we're still looking 
    > into it. If anyone knows about any other symptomatic behavior 
    > related to this problem, I'd love to hear about it.
    
    According to
    http://www.zone-h.org/en/forum/thread/forum=3/thread=4489/
    and
    http://www.immunitysec.com/CANVAS/
    
    it works only on Linux and Windows, planned but currently not working on
      Solaris(Sparc).
    
    Also interesting:
    http://www.zone-h.org/en/forum/thread/forum=3/thread=4482/
    
    Cheers,
    Juri
    
    
    ---------------------------------------------------------------------------
    Captus Networks - Integrated Intrusion Prevention and Traffic Shaping  
     - Instantly Stop DoS/DDoS Attacks, Worms & Port Scans
     - Automatically Control P2P, IM and Spam Traffic
     - Ensure Reliable Performance of Mission Critical Applications
     - Precisely Define and Implement Network Security and Performance Policies
    **FREE Vulnerability Assessment Toolkit - WhitePapers - Live Demo
    Visit us at: 
    http://www.securityfocus.com/sponsor/CaptusNetworks_incidents_030814
    ----------------------------------------------------------------------------
    



    This archive was generated by hypermail 2b30 : Wed Aug 20 2003 - 16:53:38 PDT