And…we’re back!

OK, so we had a system upgrade last week, and apparently our server didn’t really appreciate it, so wololo.net was down today, but we fixed it (’cause we rock!) hopefully this won’t happen too frequently.

Oh, and, of course, the CFW from Mad Daemon was a fake, but that was quite obvious from the start, right?

  1. H@lo World’s avatar

    important question to u wololo: Is a arithmetic overflow exploitable?

    Reply

  2. wololo’s avatar

    Some times, yes… I’ve seen cases when such an overflow coupled with bad mallocs could do things… but it’s not as easy as a buffer overflow from my (short) experience

    Reply

  3. H@lo World’s avatar

    I got this in psplink by hex editing the tiff crash of CoD3r.
    Does that mean there´s a litle hope?

    Reply

  4. H@lo World’s avatar

    Here a picture of psplink: http://s11b.directupload.net/file/d/2072/lrg285we_jpg.htm
    but it is very dificullt to controll the bytes

    Reply

  5. wololo’s avatar

    If you have no control on the values of either v0 or v1, probably not very useful… otherwise… well it could be interesting, but it doesn’t look like a simple hack

    Reply

  6. H@lo World’s avatar

    yes i know, =(
    i´m really interesed in exploit this picture.
    I do this in Hex Editor.Can u plz tell me how to load tiff files in C or ruby?
    on my programm (Dev C++) it looks so: http://s10.directupload.net/file/d/2072/3g4fexi2_jpg.htm

    Reply

  7. wololo’s avatar

    In C:
    1) install libtiff http://www.libtiff.org/
    2) There should be samples in the documentation

    Reply

  8. H@lo World’s avatar

    thank u , i downloaded the setup libtiff and i installed it. But how do i use this now? If i open a tiff image in Dev C it is like before. Have i done something wrong?

    Reply

  9. wololo’s avatar

    Read the libtiff documentation, I cannot teach you the basics of programming :(

    Reply

  10. H@lo World’s avatar

    a stupid question from me. i meant something else ,but that´s now clear for me :)
    Thank you

    Reply

Reply

Your email address will not be published. Required fields are marked *

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>