exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

shixxnote6.txt

shixxnote6.txt
Posted Oct 24, 2004
Authored by Luigi Auriemma | Site aluigi.altervista.org

A buffer overflow vulnerability exists in the field used to specify the font to use in the messages sent by Shixxnote 6.net. If this specific field is bigger than 1698 bytes the return address will be fully overwritten.

tags | advisory, overflow
SHA-256 | b65e626cc9a52695eb35f414d38bf9cf83b5124622a454bb84f0e9045e7d5aff

shixxnote6.txt

Change Mirror Download

#######################################################################

Luigi Auriemma

Application: ShixxNote 6.net
https://www.shixxnote.com
Versions: 6.net, doesn't exist a specific version or build number
but the latest change in Readme.txt (something similar to
a changelog) is 117
Platforms: Windows
Bug: buffer-overflow
Exploitation: remote
Date: 13 October 2004
Author: Luigi Auriemma
e-mail: aluigi@altervista.org
web: https://aluigi.altervista.org


#######################################################################


1) Introduction
2) Bug
3) The Code
4) Fix


#######################################################################

===============
1) Introduction
===============


>From the author:

"ShixxNOTE 6.net is a personal organizer, desktop sticky notes
(post-it) program, instant messaging application (LAN messanger) and a
communications tool used across a local network (Intranet), Internet
and via email. Perfect and ideal tool for your LAN or office
communication."


#######################################################################

======
2) Bug
======


Exists a buffer-overflow vulnerability in the field used to specify the
font to use in the messages sent by Shixxnote.
If this specific field is bigger than 1698 bytes the return address
will be fully overwritten.


#######################################################################

===========
3) The Code
===========


https://aluigi.altervista.org/poc/shixxbof.zip


#######################################################################

======
4) Fix
======


No fix.
The author is not sure if will release a new version.


#######################################################################


---
Luigi Auriemma
https://aluigi.altervista.org

Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    69 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close