请输入您要查询的百科知识:

 

词条 Przemysław Frasunek
释义

  1. Vulnerability research

  2. References

  3. External links

{{notability|Biographies|date=January 2014}}{{Infobox person
| name = Przemysław Frasunek
| image =
| alt =
| caption =
| birth_name =
| birth_date = {{Birth date and age|1983|05|06}}
| birth_place = Lublin, Poland
| death_date =
| death_place =
| nationality = Polish
| other_names =
| occupation =
| known_for =
}}

Przemysław Frasunek (also known as venglin, born May 6, 1983) is a "white hat" hacker from Poland. He has been a frequent Bugtraq poster since late in the 1990s,[1] noted for one of the first published successful software exploits for the format string bug class of attacks,[2][3] just after the first exploit of the person using nickname tf8.[4][5] Until that time the vulnerability was thought harmless.

Vulnerability research

Notable vulnerabilities credited to Przemysław Frasunek:

  • CVE-2000-0573, Format string bug in WU-FTPD (remote root exploit), one of the first exploits for the format string bug class of attacks.
  • CVE-2001-0414, Buffer overflow (remote root exploit) in NTP server, affecting wide range of systems.[6][7][8]
  • CVE-2004-0794, Signal race condition in FTP server, affecting NetBSD and Mac OS X.[9]
  • CVE-2005-2072, Privilege escalation (local root exploit) affecting Solaris versions 8, 9, 10 and OpenSolaris operating systems, discovered two weeks after public release of the OpenSolaris.[10]
  • 2001 - FreeBSD 4.4 arbitrary file access vulnerability[11][12]
  • Kernel mode race condition exploit affecting FreeBSD 6.4.[13][14]
  • Kernel mode race condition exploit affecting FreeBSD 7.0.[15]
  • CVE-2010-4210 Kernel mode null pointer dereference exploit affecting FreeBSD 7.0 to 7.2.[16]

References

{{BLP sources|date=January 2008}}
1. ^WWW page on Frasunek's security research
2. ^Software exploit for the WU-FTPD format string vulnerability
3. ^{{cite book |title=Cyber Security Essentials |page=136 |last1=Graham |first1=James |last2=Howard |first2=Richard |year=2011 }}
4. ^tf8's version of the wu-ftpd 2.6.0 exploit
5. ^scut / team-teso Exploiting Format String Vulnerabilities v1.2 September 9, 2001
6. ^NTP vulnerability, Cisco
7. ^Vulnerabilities database, Securityfocus
8. ^US-CERT Vulnerability Note
9. ^ , Secunia
10. ^Secunia Advisory on Sun Solaris 8/9/10 vulnerability
11. ^{{cite book |title=The Art of Software Security Assessment: Identifying and Preventing Software Vulnerabilities |last1=Dowd |first1=Mark |last2=McDonald |first2=John |year=2007 }}
12. ^ 
13. ^[https://www.theregister.co.uk/2009/09/14/freebsd_security_bug/ The Register article on FreeBSD 6.4 vulnerability]
14. ^FreeBSD Security Advisory
15. ^FreeBSD Security Advisory
16. ^FreeBSD Security Advisory

External links

  • {{official website|http://www.frasunek.com/}}
  • Exploits by Przemyslaw Frasunek at Exploit Db
{{authority control}}{{DEFAULTSORT:Frasunek, Przemyslaw}}{{Poland-bio-stub}}

4 : 1983 births|Living people|Computer security specialists|Polish computer scientists

随便看

 

开放百科全书收录14589846条英语、德语、日语等多语种百科知识,基本涵盖了大多数领域的百科知识,是一部内容自由、开放的电子版国际百科全书。

 

Copyright © 2023 OENC.NET All Rights Reserved
京ICP备2021023879号 更新时间:2024/11/11 4:54:59