[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Full-Disclosure] question regarding CAN-2004-0930



--On Tuesday, November 16, 2004 03:16:44 PM +0100 Christian Kujau <evil@xxxxxxxxxx> wrote:

"ls" returned *instantly* with "No such file or directory" and smbd did not go crazy. now i ask myself: how comes?

Because in the former case you were attempting to access a file through the daemon. In the latter, you were attempting to access a file through a unix utility. The former (smbd) is vulnerable. The latter (ls) apparently is not.

Paul Schmehl (pauls@xxxxxxxxxxxx)
Adjunct Information Security Officer
The University of Texas at Dallas
AVIEN Founding Member
http://www.utdallas.edu

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html