hacking security forum

Re: [Full-Disclosure] Buffer Overflow in ActivePerl ?

From: morning_wood <se_cur_ity@hotmail.com>
Date: Mon May 17 2004 - 18:44:47 EDT

>Can anybody reproduce this?

Microsoft Windows XP [Version 5.1.2600]
(C) Copyright 1985-2001 Microsoft Corp.

C:\>perl -e "$a="A" x 256; system($a)"
'AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAA' is not recognized as an internal or external command,
operable program or batch file.

[BIG CRASH HERE]

C:\>perl -v

This is perl, v5.6.1 built for MSWin32-x86-multi-thread

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
Received on Mon May 17 19:08:48 2004

This archive was generated by hypermail 2.1.8 : Mon May 17 2004 - 20:06:53 EDT