regreSSHion: Remote Unauthenticated Code Execution Vulnerability in OpenSSH server
by ssveCY008 - Monday July 1, 2024 at 02:37 PM
#11
(Jul 02, 2024, 10:23 AM)Lokie Wrote: There is a PoC for certain i386 (32-bit) versions of OpenSSH where glibc is at a static base address, so no ASLR bypass is needed.

Since the approx exploitation time (or efforts, which is ~10k requests) is based on i386, it can be assumed that newer systems (those running x86_64 / AMD64) would take a lot longer to exploit due to the need for an ASLR bypass.

Late to the party but... from what I know, you'd have to send 3 particular packets that would have to include the exact memory return address via a bruteforce operation. ASLR would increase the bruteforce space. This is a real exploit but I only see it being real world exploitable on IoT devices.

Probability of exploitation, the chance of exploitation is above 0 without updating.
Looking for Python WebDev to Help Build a PubNet Site
DM Me Fentanyl Supply Chain Info
Reply
#12
(Jul 08, 2024, 04:49 PM)someone_33 Wrote:
(Jul 02, 2024, 10:17 AM)rslimetempest Wrote: What's the query in shodan to search all openssh?

The query for Shodan is product:"OpenSSH"

This is great. Thanks man!

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  BreachForums Leak Free Data KingJulien 178 13,147 Yesterday, 10:25 AM
Last Post: HidanG
  News: Pitney Bowes Breached. dai5 0 145 Yesterday, 08:43 AM
Last Post: dai5
  PDF Exploit Builder by TheStrain – worth it? xXTH3_R3DXx 0 173 Yesterday, 03:28 AM
Last Post: xXTH3_R3DXx
  Corruptiion of PLN [Indonesia] - 2025 Investigation Viral LordZeroDay 25 1,558 Apr 25, 2026, 09:23 PM
Last Post: dipiwef113
  The Ratification of the TNI Bill, Has an Impact on Indonesia? LordZeroDay 12 782 Apr 25, 2026, 02:50 PM
Last Post: dipiwef113

Forum Jump:


 Users browsing this forum: 1 Guest(s)