[Full-disclosure] UnixWare 7.1.4 : LibTIFF < 3.72 malformed data code exec

KF (lists) kf_lists at digitalmunition.com
Wed Sep 21 06:15:14 BST 2005


Even more comical is how they STILL can't patch that old ftp server of 
theirs. SITE EXEC loves SCO.

Honeypot or stupidity, you decide...

kfinisterre at animosity:~$ ftp ftpput.sco.com
Connected to ftpput.sco.com.
220 artemis FTP server (Version 2.1WU(1)) ready.
Name (ftpput.sco.com:kfinisterre): anonymous
331 Guest login ok, send e-mail address as password.


-KF



Tim wrote:

>>Wow!!
>>
>>Are they still around??
>>    
>>
>
>Yeah, comical isn't it?
>
>They frequently release patches for 4-6 month old holes.  They are kinda
>like the Microsoft[1] of the Unix/Linux world.  
>
>tim
>
>
>1.  http://www.eeye.com/html/research/upcoming/index.html
>_______________________________________________
>Full-Disclosure - We believe in it.
>Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>Hosted and sponsored by Secunia - http://secunia.com/
>
>
>
>  
>




Full-Disclosure is hosted and sponsored by Secunia.