regreSSHion: Remote Unauthenticated Code Execution Vulnerability in OpenSSH server
by ssveCY008 - Monday July 1, 2024 at 02:37 PM
#11
(Jul 02, 2024, 10:23 AM)Lokie Wrote: There is a PoC for certain i386 (32-bit) versions of OpenSSH where glibc is at a static base address, so no ASLR bypass is needed.

Since the approx exploitation time (or efforts, which is ~10k requests) is based on i386, it can be assumed that newer systems (those running x86_64 / AMD64) would take a lot longer to exploit due to the need for an ASLR bypass.

Late to the party but... from what I know, you'd have to send 3 particular packets that would have to include the exact memory return address via a bruteforce operation. ASLR would increase the bruteforce space. This is a real exploit but I only see it being real world exploitable on IoT devices.

Probability of exploitation, the chance of exploitation is above 0 without updating.
Looking for Python WebDev to Help Build a PubNet Site
DM Me Fentanyl Supply Chain Info
Reply
#12
(Jul 08, 2024, 04:49 PM)someone_33 Wrote:
(Jul 02, 2024, 10:17 AM)rslimetempest Wrote: What's the query in shodan to search all openssh?

The query for Shodan is product:"OpenSSH"

This is great. Thanks man!

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Tanaka - Moderator of PF and BF leak Real Email Address unret 0 76 8 hours ago
Last Post: unret
  Digital Surveillance and the Cybersecurity Crisis in Turkey Tr28 0 80 9 hours ago
Last Post: Tr28
  Im Tanaka, and i am using real email (moderator of PwnForums and DarkForums) unret 1 182 Yesterday, 10:51 PM
Last Post: digits
  Brent crude oil. dai5 2 287 Yesterday, 11:21 AM
Last Post: phas3lock
  Where to buy cheap Monopoly Go Stickers? IGGM is the best choice. Kingloud 0 120 Yesterday, 10:42 AM
Last Post: Kingloud

Forum Jump:


 Users browsing this forum: