From owner-freebsd-security@FreeBSD.ORG Wed Nov 11 19:37:51 2009 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id EB8B21065676 for ; Wed, 11 Nov 2009 19:37:51 +0000 (UTC) (envelope-from rea-fbsd@codelabs.ru) Received: from 0.mx.codelabs.ru (0.mx.codelabs.ru [144.206.177.45]) by mx1.freebsd.org (Postfix) with ESMTP id 98A088FC14 for ; Wed, 11 Nov 2009 19:37:51 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=codelabs.ru; s=two; h=Date:From:To:Cc:Subject:Message-ID: Reply-To:References:MIME-Version:Content-Type:In-Reply-To: Sender; bh=14Mh88SnmAcXluyqswuY2Lw30dZiw3fwtq8cP/Rw5fg=; b=bkcOj muUPFiItPdT7Y2pBiEElrmM9SdjC6uxdCpu/OIUBm8WTbzbxWQ2U9yV0Ynxf0tb3 vOIhqqKikQYfpc2IzyD75t3fmP7PzQlwUTZUUPN70mtleVqiEllhVK1NMSVzQOJZ dDIsjeLKV2LhHJvgTtD4q7kBhBpuUsxGAKw02kKBx/tflJ1xJW9UBVr31UJSUFe3 N/EL/Y/P8G+Uj2XxeNR9culNrnYmcNJppSErnPdlV6MwEB2DeDomK6iNUOA5HpQF iXJSHDv9woLcGi3Xe62ZeOhQxjvb0MFedPcVe/k9YbF28rqVTZqTtE4VLUFP+zRO lVbtCcUUOk+c1EOMA== Received: from shadow.codelabs.ru (cdma-92-36-8-47.msk.skylink.ru [92.36.8.47]) by 0.mx.codelabs.ru with esmtpsa (TLSv1:AES256-SHA:256) id 1N8J0l-000Ijt-SO; Wed, 11 Nov 2009 22:37:49 +0300 Date: Wed, 11 Nov 2009 22:37:44 +0300 From: Eygene Ryabinkin To: Damian Weber Message-ID: References: <6101e8c40907201008n62eeec05r6670a79698bc2ac7@mail.gmail.com> <20091111173311.T37440@maildrop.int.zabbadoz.net> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: Sender: rea-fbsd@codelabs.ru Cc: "Bjoern A. Zeeb" , Oliver Pinter , wkoszek@freebsd.org, freebsd-security@freebsd.org Subject: Re: 2009-07-20 FreeBSD 7.2 (pecoff executable) Local Denial of Service Exploit 23 R D Shaun Colley X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list Reply-To: rea-fbsd@codelabs.ru List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 11 Nov 2009 19:37:52 -0000 Wed, Nov 11, 2009 at 07:14:48PM +0100, Damian Weber wrote: > FWIW, I got another result on 6.4-STABLE > > FreeBSD mymachine.local 6.4-STABLE FreeBSD 6.4-STABLE #6: Sat Oct 3 13:06:12 CEST 2009 root@hypercrypt.local:/usr/obj/usr/src/sys/MYMACHINE i386 > > $ ./pecoff > MZaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa????aaaa > [I'm truncating here, ~3500 a's follow]aaaaa: File name too long You have no pecoff module loaded or compiled-in to the kernel, aren't you? Your "File name too long" is spitted by the shell, so it was not handled by the PE loader at all. -- Eygene _ ___ _.--. # \`.|\..----...-'` `-._.-'_.-'` # Remember that it is hard / ' ` , __.--' # to read the on-line manual )/' _/ \ `-_, / # while single-stepping the kernel. `-'" `"\_ ,_.-;_.-\_ ', fsc/as # _.-'_./ {_.' ; / # -- FreeBSD Developers handbook {_.-``-' {_/ #