Emule Web Control Panel HTTP Login Long Password Denial of Service Vulnerability
BID:8854
Info
Emule Web Control Panel HTTP Login Long Password Denial of Service Vulnerability
| Bugtraq ID: | 8854 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 20 2003 12:00AM |
| Updated: | Oct 20 2003 12:00AM |
| Credit: | This issue was reported by "The-Insider" <[email protected]>. |
| Vulnerable: |
Emule Emule 0.29 c |
| Not Vulnerable: | |
Discussion
Emule Web Control Panel HTTP Login Long Password Denial of Service Vulnerability
It has been reported that the eMule Web Control Panel HTTP login mechanism may be prone to denial of service attacks. The issue is said to occur due to the mechanism failing to verify the origin of data transmitted via a login form. As a result, eMule expects a limited number of password characters to be transmitted when attempting to login. By making use of a malicious form, it may be possible for an attacker to transmit excessive data to eMule and effectively trigger a denial of service.
It has been reported that the eMule Web Control Panel HTTP login mechanism may be prone to denial of service attacks. The issue is said to occur due to the mechanism failing to verify the origin of data transmitted via a login form. As a result, eMule expects a limited number of password characters to be transmitted when attempting to login. By making use of a malicious form, it may be possible for an attacker to transmit excessive data to eMule and effectively trigger a denial of service.
Exploit / POC
Emule Web Control Panel HTTP Login Long Password Denial of Service Vulnerability
A proof-of-concept HTML form has been made available, however due to it's length it will not be included below. Please see the referenced Bugtraq post for the form example. This could also be exploited with a number of publicly available utilities, such as curl.
A proof-of-concept HTML form has been made available, however due to it's length it will not be included below. Please see the referenced Bugtraq post for the form example. This could also be exploited with a number of publicly available utilities, such as curl.
Solution / Fix
Emule Web Control Panel HTTP Login Long Password Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Emule Web Control Panel HTTP Login Long Password Denial of Service Vulnerability
References:
References:
- eMule 2.2 [0.29c] - Web Control Panel - DOS(Denial Of Service) ("The-Insider"
)