back

by dafelst·3y ago·view on hn ↗
How the hell is there an RCE in ICMP in 2023?

I remember exploiting fragmented ICMP packets on Windows 95 in like 1996 to blue-screen people using the IcEbx extension for the BitchX IRC client, I think the exploit was called sping maybe? The fact that a such a vulnerability can even exist in such fundamental code these days is mind boggling, especially when bugs in the same family were around in that stack 25+ years ago.

Between this and today's TPM exploit, I have to admit the RiiR folks are starting to have a point.

2 comments
It's a buffer overflow error, not a lifetime management error.
So one more thing that Rust fixes, got it.
ssping and good ol' winnuke ah and 'land'.. ... oh memories.