Re: Re: XChat 2.8.4-1 - Multiple Vulnerabilities

看板Bugtraq作者時間17年前 (2008/04/01 03:13), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串3/3 (看更多)
>1) Password disclosure >What priviledges on the system do you need to >read that process memory? >With such priviledges, why don't you read the >data directly from the >config file? You can try to use the evil's ProcessMemoryDumper. I dumped (and I've obtained user password) the memory from a limited User. >2) Local Dos >Is the build unoficial/unsupported from the XChat >team? Does the same >bug exists in the official builds? I've not tested the Official release. >You talk about a local dos.. how can a user access >the tray icon of >another user to trigger the crash? The "bug" was found while I was working in a VPN.. Regards.
文章代碼(AID): #17yJV600 (Bugtraq)
文章代碼(AID): #17yJV600 (Bugtraq)