AnalogX Proxy Socks4A Buffer Overflow Vulnerability

The following was provided as an example of how to reproduce this issue:

Send a Sock4a request to the target system on TCP port 1080 consisting
of a hostname section of 140 or more characters will cause a write
access violation application error.

An example TCP packet to send is

\x04\x01\x04\x38\x00\x00\x00abcd\x00#\x00

where the '\xXX' characters signify their corresponding HEX binary values and
the '#' is substituted with the DNS name of 140 or more characters.

Exploit released by Kanatoko <anvil@jumperz.net>.


 

Privacy Statement
Copyright 2010, SecurityFocus