[Full-Disclosure] Automated SSH login attempts? Related Cross post from incidents.org

Jirka Kosina jikos at jikos.cz
Sun Aug 1 16:49:04 BST 2004


On Fri, 30 Jul 2004, Harris, Michael C. wrote:

> We got zapped by some hackers from, I think, Romania that have a priv
> escalation exploit for Linux 2.4.20
> http://sirzion.illusivecreations.com/loginxy

This exploit really shouldn't be dangerous for any admin updating at least 
once a year <g> - it is just a scriptkiddie exploit for old do_brk() 
bounds check vulnerability.

-- 
JiKos.




Full-Disclosure is hosted and sponsored by Secunia.