Re: UFS Bug: FreeBSD 6.1/6.2/7.0: MOKB-08-11-2006, CVE-2006-5824, MOKB-03-11-2006, CVE-2006-5679

2006-11-24 Thread Lutz Boehne
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 [It's just a panic] I was so transfixed on Josh stating that the attacker could as well just mount a filesystem with suid root binaries and how that would be more useful than a buffer overflow in the filesystem driver. I totally missed the fact that we

Re: UFS Bug: FreeBSD 6.1/6.2/7.0: MOKB-08-11-2006, CVE-2006-5824, MOKB-03-11-2006, CVE-2006-5679

2006-11-24 Thread Lutz Boehne
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 > Out of the box you need to be root to mount things. Once you have > root access to a box you don't need silly things like this to crash > it. > > If you've gone out of your way to configure your box in such a way > that a non-root user can mount

Re: PE disassembler for unix

2006-06-05 Thread Lutz Boehne
Hi, > Hello, I'm looking for a disassembler to examine a malicious > Win32 binary on FreeBSD. Does anybody have any favourites? editors/hte (http://hte.sourceforge.net/) is fairly nice, disassembles ELF, PE and some other binary formats. Regards, Lutz pgpUdXdIJKFQI.pgp Description: PGP signa