Re: Buffer overflow in sperl5.003 (fwd)

----- Forwarded message from David Luyer -----

>From owner-bugtraq@NETSPACE.ORG  Fri Apr 18 13:56:55 1997
Approved-By: aleph1@UNDERGROUND.ORG
Message-ID:  <>
Date:         Fri, 18 Apr 1997 11:12:04 +0800
Reply-To: David Luyer <luyer@UCS.UWA.EDU.AU>
Sender: Bugtraq List <BUGTRAQ@NETSPACE.ORG>
From: David Luyer <luyer@UCS.UWA.EDU.AU>
Subject:      Re: Buffer overflow in sperl5.003
X-To:         Murphy <jtmurphy@CRAY1.ECST.CSUCHICO.EDU>
In-Reply-To:  <>

On Thu, 17 Apr 1997, Murphy wrote:
> Attached is the source for the exploit. Since it requires some work to
>be done to the compiled exploit (Stripping of 5 byte at the begining and
>end of the binary), the precompiled Linux x86 exploit can be found at

Note that the exploit tries offsets of 1170 to 1240.  Debian Linux with
sperl5.00307 requires a value of 1169 (and is vulnerable).


----- End of forwarded message from David Luyer -----

Thomas Koenig,, ig25@dkauni2.bitnet.
The joy of engineering is to find a straight line on a double
logarithmic diagram.

