lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Tue, 24 Mar 2009 11:46:10 +0000
From: mu-b@...it-labs.org
To: full-disclosure@...ts.grok.org.uk
Subject: Re: FreeBSD/OS X kernel bug dump

thanks to the person who bothered to let me know the links were *slighty*
wrong, that is what you get trying to stay awake to beat jet-lag...

Quoting mu-b@...it-labs.org:

> All - the following are the exploits from the recent demonstrations at
>
> Apple Mac OSX >= 10.4.0 local kernel root
>

http://www.digit-labs.org/files/exploits/xnu-hfs-fcntl-v2.c
http://www.digit-labs.org/files/exploits/xnu-hfs-fcntl-v2.sh

>
> FreeBSD >= 7.0 ktimer local kernel root
> (http://security.freebsd.org/advisories/FreeBSD-SA-09:06.ktimer.asc)
>
> http://www.digit-labs.org/files/exploits/bsd-ktimer.c
>
> other random stuff..
>
> http://www.digit-labs.org/files/exploits/xnu-macfsstat-leak.c
> http://www.digit-labs.org/files/exploits/xnu-profil-leak.c
> http://www.digit-labs.org/files/exploits/xnu-appletalk-zip.c
>
> all the above are old now, but still exist today...
>
> christer/mu-b
> --
> mu-b
> (mu-b@...it-labs.org)
>
>    "Only a few people will follow the proof. Whoever does will
>       spend the rest of his life convincing people it is correct."
>          - Anonymous, "P ?= NP"
>
> _______________________________________________
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ