Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: [Full-disclosure] [levent@corehack.org: Re: [Amsn-devel] aMSN <= 0.96 remote DoS vulnerability] |
|---|---|
| Date: | Sun, 22 Apr 2007 18:22:23 +0200 |
On Sun, Apr 22, 2007 at 07:06:15PM +0300, Ismail D?nmez wrote:
On Sunday 22 April 2007 18:51:39 Levent Kayan wrote: [...]31337 is just an example port! aMSN is binding an ephermal port after you've started it. Just do a netstat -an and look for ephermal ports. If you get the aMSN port you can connect to it and sending some characters and you'll get replies by aMSN. If you send an '{' or '}' character to that amsn port, you'll notice that aMSN is reporting an error message (amsn window). But if you going to send more than one character of '}' or '{' it will be killed. Yes, the whole client! To "Ismail Soenmez":Learn to spell my name correctly first.What about "DDoS"? Sending characters to that port in an "infinite" loop is a DDoS for you?If you read the PoC you wrote you'll see that you forgot to increment the value of i in the loop. So yes you are sending packages in an infinite loop. Thats DoS, never mind the double D I stuck up there. -- Life is a game, and if you aren't in it to win, what the heck are you still doing here? -- Linus Torvalds (talking about open source development)
It was just a typo about your name (i'm using .de layout). Like you with your "DDoS" typo. I didn't want to increment, just doing a infinite loop yes! You can do it manually connecting to that port and just paste the characters I showed. The loop isn't important in that role. Same result. Cheers "DOENMEZ"
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
-- Name: Levent Kayan E-Mail: levent@corehack.org GPG key: 0xd6794965 Key fingerprint: FD20 03C3 DD7F 51BB 224F F11E 0855 23C8 D679 4965 Website: http://www.corehack.org/ _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: [Full-disclosure] [Amsn-devel] aMSN <= 0.96 remote DoS vulnerability, Ismail Dönmez |
|---|---|
| Next by Date: | Re: [Full-disclosure] Apparently eEye's blog got p0wnd, Paul Schmehl |
| Previous by Thread: | [Full-disclosure] [SECURITY] [DSA 1279-1] New webcalendar packages fix cross-site scripting, Moritz Muehlenhoff |
| Next by Thread: | [Full-disclosure] [ GLSA 200704-16 ] Aircrack-ng: Remote execution of arbitrary code, Raphael Marichez |
| Indexes: | [Date] [Thread] [Top] [All Lists] |