BugTraq
silc question - insecure memory Feb 01 2003 04:44AM
cdowns (cdowns angrypacket com) (1 replies)
Good Evening,
while screwing around tonight checking memory for the SSH2
advisory. I noticed passphrase and complete sessions from silc in
memory. I dont know if this is normal for silc ( I wouldnt think it
would be ) but all you need to do it is:

cdowns@Vader:~$ sudo dd if=/dev/mem of=/home/cdowns/mem.dump | less
~cdowns/mem.dump

then just search for you key phrase.

~!>D

--
------------------------------------------
http://www.angrypacket.com
Christopher M Downs,RHCE
cdowns (at) angrypacket (dot) com [email concealed]

char ash[]="\x48\x61\x69\x6C\x20"
"\x74\x6F\x20\x74\x68\x65\x20\x4B"
"\x69\x6E\x67";
-------------------------------------------

[ reply ]
Re: silc question - insecure memory Feb 01 2003 01:44PM
Florian Weimer (Weimer CERT Uni-Stuttgart DE)


 

Privacy Statement
Copyright 2010, SecurityFocus