ParaChat Phantom User Denial Of Service Vulnerability
BID:5370
Info
ParaChat Phantom User Denial Of Service Vulnerability
| Bugtraq ID: | 5370 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 31 2002 12:00AM |
| Updated: | Jul 31 2002 12:00AM |
| Credit: | Discovery of this issue is credited to Matt Smith (RatMan) <[email protected]> and Amy Marie (DraculaWoman) <[email protected]>. |
| Vulnerable: |
ParaChat ParaChat Server 4.0 |
| Not Vulnerable: | |
Discussion
ParaChat Phantom User Denial Of Service Vulnerability
ParaChat chat servers are prone to a denial of service condition.
If a user has left the webpage for a chat room using the Back or Forward buttons of their browser in lieu of logging out, their account will still be logged into the chat room until it times out 15 minutes later. A malicious user may do this repeatedly as different users to overload the chat server with "phantom" users. A denial of service may be the result.
ParaChat chat servers are prone to a denial of service condition.
If a user has left the webpage for a chat room using the Back or Forward buttons of their browser in lieu of logging out, their account will still be logged into the chat room until it times out 15 minutes later. A malicious user may do this repeatedly as different users to overload the chat server with "phantom" users. A denial of service may be the result.
Exploit / POC
ParaChat Phantom User Denial Of Service Vulnerability
This issue may be exploited with a web browser.
This issue may be exploited with a web browser.