Posted by Valdis . Kletnieks on Apr 28
On Thu, 28 Apr 2011 14:40:22 -0300, Mario Vilas said:
Who cares? You got code executed on the remote box, that's the *hard* part.
Use that to inject a callback shell or something, use *that* to get yourself a shell
prompt. At that point, download something else that exploits you to root – if
you even *need* to, as quite often the Good Stuff is readable by non-root
users.
Source: Re: Insect Pro – Advisory 2011 0428 – Zero Day – Heap Buffer Overflow in xMatters APClient




