Currently I know of three serious attack vectors:
- crafted cgi parameters from a web client
- dhclient getting crafted hostnames from a DHCP server
- restricted SSH users getting full shell access
I realise this may be too wide of a question, but I did not find any such info as of yet, only vague guesses. (Maybe this question belong to the community wiki.)
I am interested mainly in:
- client services like the dhclient
- server services like the cgi/ssh attack
- desktop clients accessing the network like a web browser, ftp client, etc. (i have not heard anything like that yet)