Are you sure tha /dev/urandom will never return a string with %[snpfdn] etc? Your exploit may be exploitable ;) On Friday 05 October 2001 12:19 am, Petr Baudis wrote: > > for(;;) > { > fgets(buffer, sizeof(buffer), fp); > syslog(0, buffer); > } Fix: syslog(0, "%s", buffer); -- H D Moore http://www.digitaldefense.net - work http://www.digitaloffense.net - play
This archive was generated by hypermail 2b30 : Fri Oct 05 2001 - 10:23:07 PDT