PornoSecurity: sexy vulns, porno sploits and the like

Oracle WebLogic Connector JSESSIONID BoF exploit

Posted on 2009-04-01 17:30:43 in PornoSecurity

So, I wrote this some time ago and there's no reason to keep it private anymore. You can find it here as usual(submitted now, could need a couple of hours to be published).

This is CVE-2008-5457 and it was an "unspecified vulnerability" so I had to reverse engineer the patch provided by oracle.
I wrote a nice post with technical infos at http://www.securitydate.it

Nick