Monkey HTTP Server Invalid POST Request Denial Of Service Vulnerability
BID:6096
Info
Monkey HTTP Server Invalid POST Request Denial Of Service Vulnerability
| Bugtraq ID: | 6096 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2002-1663 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 02 2002 12:00AM |
| Updated: | Mar 19 2015 09:28AM |
| Credit: | Vulnerability announced in the product changelog. |
| Vulnerable: |
Monkey-Project Monkey Http Daemon 0.5 Monkey-Project Monkey Http Daemon 0.4.2 Monkey-Project Monkey Http Daemon 0.4.1 Monkey-Project Monkey Http Daemon 0.4 |
| Not Vulnerable: |
Monkey-Project Monkey Http Daemon 0.5.1 |
Discussion
Monkey HTTP Server Invalid POST Request Denial Of Service Vulnerability
A denial of service vulnerability has been reported for Monkey HTTP server. The vulnerability is due to inadequate checks being performed when decoding POST requests.
An attacker can exploit this vulnerability by issuing a POST request with an invalid Content-Length header, or without a Content-Length value. When the server attempts to service the request, it will crash and lead to the denial of service condition.
A denial of service vulnerability has been reported for Monkey HTTP server. The vulnerability is due to inadequate checks being performed when decoding POST requests.
An attacker can exploit this vulnerability by issuing a POST request with an invalid Content-Length header, or without a Content-Length value. When the server attempts to service the request, it will crash and lead to the denial of service condition.
Exploit / POC
Monkey HTTP Server Invalid POST Request Denial Of Service Vulnerability
The following proof of concept was provided:
POST / HTTP/1.1
Host: 127.0.0.1:2001
Content-Length: 1
The following proof of concept was provided:
POST / HTTP/1.1
Host: 127.0.0.1:2001
Content-Length: 1
References
Monkey HTTP Server Invalid POST Request Denial Of Service Vulnerability
References:
References:
- Monkey HTTP Daemon Product Page (Monkey)