VERITAS NetBackup Java User-Interface Remote Format String Vulnerability

Exploits for Windows, Linux, and Mac OS X platforms have been supplied by <johnh@digitalmunition.com> & <kf@digitalmunition.com>.

VERITAS-Linux.pl.gpg:

pass: allaroundthemulberrybush

VERITAS-OSX.pl.gpg:

pass: themonkeychasedtheweasel

VERITAS-WIN32.pl.gpg:

pass: apennyforaneedle

The following exploit is available to members of the Immunity Partner's Program:

https://www.immunityinc.com/downloads/immpartners/netbackup_javaui.tgz

UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.


 

Privacy Statement
Copyright 2010, SecurityFocus