Re: possible 0-day exploit for latest Real-/Helixserver 9.0.2.794

From: Brian Benitez (brianat_private)
Date: Sun Aug 24 2003 - 23:40:56 PDT

  • Next message: Gereon Volker: "Outgoing connections to ports 22226 and 22227"

    
     ('binary' encoding is not supported, stored as-is)
    In-Reply-To: <20030820114627.GA25765at_private>
    
    Dunno if everyone has seen this, but Real has posted a temporary 
    fix for this issue:
    
    http://service.real.com/help/faq/security/
    rootexploit082203.html
    
    It's not a new version but if you remove some of the server plug-
    ins  (the View Source plugins) then the exploit no longer works.
    
    Hope this helps,
    
    Brian
    
    ---------------------------------------------------------------------------
    Attend Black Hat Briefings & Training Federal, September 29-30 (Training), 
    October 1-2 (Briefings) in Tysons Corner, VA; the world's premier 
    technical IT security event.  Modeled after the famous Black Hat event in 
    Las Vegas! 6 tracks, 12 training sessions, top speakers and sponsors.  
    Symantec is the Diamond sponsor.  Early-bird registration ends September 6.Visit us: www.blackhat.com
    ----------------------------------------------------------------------------
    



    This archive was generated by hypermail 2b30 : Tue Aug 26 2003 - 08:35:30 PDT