Re: Looking for exploits

From: Bram Shirani (kamat_private)
Date: Thu Apr 12 2001 - 10:06:18 PDT

  • Next message: Jay D. Dyson: "Re: Apache Win32 8192 string bug"

    Check packetstom.securify.com for something like that. Also - are you looking for remote exploits run on your command line but targeting another system? Or are you looking for exploits run on your system for your system? Both should be very easy to find on packetstorm, but I may be able to point you to some others if you need more.
    
    
    On Wed, Apr 11, 2001 at 12:02:22PM +0200, Marc Plaggemeier said sometin like...
    > Hello,
    >
    > perphaps the list is the right place to ask some questions about
    > the "sort of exploits".
    >
    > I am actually writing on my diploma theses about intrusion detection.
    > My system has a anomaly and a misuse detection module.
    > Now, I am looking for some exploits to test my misuse detection module.
    > It controls only commands given by the users (nothing else).
    >
    > So I was looking for some exploits which only use the commandline. No
    > shellscript or something else.
    > But I did not found so much. Most of the exploits were C-Programs or
    > shell-scripts. (using some sort of buffer overflows)
    >
    > So my question is:
    > Are there any exploits which are "based" on the commandline? (like old
    > sendmail bugs) I know there are some exploits! But how I can find some
    > of them? I searched in some archives but ...
    >
    > How many exploits are based on C-Programs or shell-scripts? Are there any
    > statistics?
    >
    > Perhaps someone can help me!
    >
    > Thanks,
    > Greetings
    > Marc Plaggemeier
    
    --
    kam at aversion.net
    The Aversion Security Team
    http://www.aversion.net
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 13:38:34 PDT