Thank you for your private message, WR. What you said makes sense to me and I can see how and why this happens from understanding the jj2 TCP network protocol. I will look into this in a bit greater detail in the near future, but I am happy to say that some code I have written (not the one I had in mind actually) is already capable of preventing this exploit as well as another exploit that is closely related to this one.
I am mostly interested in how to reproduce the second bug because it is directly related to one of my programs. Since the code I am using is very... "similar" to the one in PC4, a fix should be applied before the code can be put to use.
__________________
<a href="http://nmap.org/"><img border="0" alt="Nmap Security Scanner" src="http://images.insecure.org/nmap/images/prop/nmap_bnr_matrix_pfos.gif"/></a>
|