[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Full-disclosure] Mikrotik RouterOS 5.* and 6.* sshd remote preauth heap corruption
- To: full-disclosure@xxxxxxxxxxxxxxxxx, bugtraq@xxxxxxxxxxxxxxxxx, submissions@xxxxxxxxxxxxxxxxxxxxxxx
- Subject: [Full-disclosure] Mikrotik RouterOS 5.* and 6.* sshd remote preauth heap corruption
- From: king cope <isowarez.isowarez.isowarez@xxxxxxxxxxxxxx>
- Date: Mon, 2 Sep 2013 21:45:12 +0700
Hello lists,
here you find the analysis of a vulnerability I recently discovered.
Mikrotik RouterOS 5.* and 6.* sshd remote preauth heap corruption
http://kingcope.wordpress.com/2013/09/02/mikrotik-routeros-5-and-6-sshd-remote-preauth-heap-corruption/
Additionally it includes a way to drop into a development shell for
recent Mikrotik RouterOS versions.
Cheers :>
Kingcope
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/