On Wed, 22 Sep 2010, Gerard Hooton wrote:
> I compiled 15023.c and ran it on
> 2.6.9-67.ELsmp #1 SMP Wed Nov 7 13:56:44 EST 2007 x86_64 x86_64 x86_64
>> I got :-
> symbol table not available, aborting!
>From what I've read the bug was introduced in 2.6.26 about 2 years ago
(and back-ported by Redhat to their 2.6.18 kernel). Your kernel is too
old to be exposed. OTOH, it's so old you've probably got a host of other
issues to worry about ;-|
> > On Wed, Sep 22, 2010 at 10:19 PM, Gerard Hooton <g.hooton at ucc.ie> wrote:
> >> Where can I get the exploit code?
> > http://www.exploit-db.com/exploits/15023/> >
> >> At http://www.seclists.org/fulldisclosure/2010/Sep/268 I found a link to
> >> ABftw_c.bin called ABftw.c
> >> What is that ?
> >> How do I use it?
> > You need to compile it, start there:
> > http://www.google.ie/search?source=ig&hl=en&rlz=&=&q=how+to+compile+c+code&aq=f&aqi=g10&aql=&oq=&gs_rfai=> >
> >> What will it do?
> > It will the world as you know, a bit as if you were type google on the
> > google search engine (quote from the IT crowd :)
> > More seriously, many places you can get that exploit. As every
> > exploit, read the code first. I am not highly proficient in C, still
> > you get the gist of the exploit.
> > Steph (ps, patched on Ubuntu and Debian systems too)
> Gerard Hooton.
> Department of Microelectronic Engineering U.C.C.
> Butler Building,
> Enterprise Centre,
> North Mall.
>> Tel: +353 21 4904576
> Fax: +353 21 4904573
> Irish Linux Users' Group mailing list
> About this list : http://mail.linux.ie/mailman/listinfo/ilug> Who we are : http://www.linux.ie/> Where we are : http://www.linux.ie/map/>>
Maintained by the ILUG website team. The aim of Linux.ie is to
support and help commercial and private users of Linux in Ireland. You can
display ILUG news in your own webpages, read backend
information to find out how. Networking services kindly provided by HEAnet, server kindly donated by
Dell. Linux is a trademark of Linus Torvalds,
used with permission. No penguins were harmed in the production or maintenance
of this highly praised website. Looking for the
Indian Linux Users' Group? Try here. If you've read all this and aren't a lawyer: you should be!