Download TrojanHunter Now
Free 30-day trial!
Latest TrojanHunter Version:
TrojanHunter 5.0
Order Now
License file delivered within minutes.
Welcome, Guest. Please Login or Register.
Nov 21st, 2008, 4:55pm
   Mischel Internet Security Forum
   Internet Security
   Software
(Moderators: Helena, Gavin_Coe, Magnus)
   Proxomitron Security problem
« Previous topic | Next topic »
Pages: 1  Reply Reply  Notify of replies Notify of replies   Send Topic Send Topic   Print Print
   Author  Topic: Proxomitron Security problem  (Read 391 times)
maxqnz
Newbie
*




Walekam salaam, noho ora mai!

   
WWW  

Posts: 26
Proxomitron Security problem
« on: Feb 24th, 2003, 6:55am »
Quote Quote  Modify Modify

Summary
 
The Proxomitron Naoko is a universal web filter.
Sending a parameter with a buffer of 1024 bytes in length or more, causes Proxomitron Naoko to crash.
This vulnerability can be easily exploited to execute code.
 
Vulnerable systems:
Version 4.4 and prior
 
Solution:
No solution is available at this time.
 
Vendor Status:
The vendor has been notified.
 
Securiteam
IP Logged

ओ पालनहारे, तुमरे बिन हमरा कौनों नहीं
What's a pieriansipist?
Jamming
Stole All the Forum Stars
********




Remember when a Trojan was just for protection.

   


Gender: male
Posts: 2039
Re: Proxomitron Security problem
« Reply #1 on: Feb 25th, 2003, 10:22am »
Quote Quote  Modify Modify

This is from Scott Lemon(Proxo's Author) to another Board I am a member of (Computer Cops).  Magnus you might want to pay attention to this, if they find an exploit about any of your work.  
Quote:

If this has been a more dangerous exploit I would of had a patch out by now, but it's honestly hard for me to imagine any situation where this could be used to do harm. After all, if someone has free access to a command line on your computer they can already probably run any code they like, delete files, or trash your PC completely.  
 
There's no risk at on a personal PC (unless you enjoy exploiting yourself that is), and I'd think very few restricted multi-user Windows environments would give someone untrusted a command line that could run just any program.  
 
What annoyed me was this "exploit" was made public before I was informed, and the wording of it makes it seem like something much, much more than it really is. I don't see how you could use this to DOS anything but the Proxomtiron running on your own PC (and if that's what you want it's much easier to just click "File" and "Exit"  ). As for "Could easily be used to execute code" - hmmm, well if they have a command line to run Proxomitron, then yep it's pretty easy to execute code otherwise how could they run Proxomitron to begin with?
IP Logged

Team Z Member

Servare cives, major est virtus patriae patri.
- Lucius Annaeus Seneca
I was born an American; I live an American; I shall die an American!
- Daniel Webster
Pages: 1  Reply Reply  Notify of replies Notify of replies   Send Topic Send Topic   Print Print

« Previous topic | Next topic »
Search
Members
Login
Register