telnetd-login exploit v1.19

Vulnerability exploited: CVE-2001-0797 - BID-3681

Category: Exploits/Remote

Exploits two vulnerabilities and installs a level0 agent into the target host.
This module exploits a buffer overflow in System V login and an overflow in the TTYPROMPT telnet variable in order to install a level0 agent into the target host.The deployed level 0 agent will run with the privileges of the specified user. Any valid user, even users without a configured shell, can be used for this attack.

Supported Systems:
    Solaris 2.6 (sun4m)
    Solaris 2.6 (sun4u)
    Solaris 7 (sun4m)
    Solaris 7 (sun4u)
    Solaris 8 (sun4u)


This module is included in the latest version of CORE IMPACT, the first automated comprehensive penetration testing product for accurately identifying information security risks. Click here to learn more about the product.