Re: [MV] Urgent: Anyone accessing the internet! (HOAX)!

Todd Paisley (paisley@erols.com)
Thu, 12 Nov 1998 20:08:22 -0500

>the threat of this kind of attack is, at this stage, pretty much nil. in
>part because you still have to mess with an attachment menu / filemenu, and
>I have yet to see anyone actually infect a machine with it.. there's a big
>difference between crash a machine and format a harddrive..

You don't have to mess with the menu. If written correctly, why would it
crash? As long as I know what processor you are running (And I'll guess by
saying it is a Intel processor and be correct 90% of the time.), getting it
to execute anything would be easy by inserting the correct 80X86 assembly
instructions. Very trivial to perform using basic hacker buffer overflow
techniques. (There are a plethora of generic routines to exploit buffer
overflows for a variety of processors. Once I know the buffer size of the
mail file attachment field, I just need to "plug and play" these generic
routines in the location following the location that creates the overflow.
It is a very common exploit these days to go after buffer overflows.)
You're only hope would be if your ISP is prescanning the header for
non-printable ASCII characters (if you are foolish enough to think this is
in the realm of black helicopters).

While "WIN A HOLIDAY" is a hoax, the techniques they describe a very real.

Sorry to ramble off topic. I just hated to see Mike get plastered for
something that IS a real problem.

Todd Paisley

===
To unsubscribe from the mil-veh mailing list, send the single word
UNSUBSCRIBE in the body of a message to <mil-veh-request@skylee.com>.