[NT] Chat Anywhere DoS
From: SecuriTeam (support_at_securiteam.com)
Date: 09/02/04
- Previous message: SecuriTeam: "[EXPL] Courier-IMAP Remote Format String Vulnerability Exploit"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
To: list@securiteam.com Date: 2 Sep 2004 12:51:18 +0200
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
The SecuriTeam alerts list - Free, Accurate, Independent.
Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html
- - - - - - - - -
Chat Anywhere DoS
------------------------------------------------------------------------
SUMMARY
<http://www.lionmax.com/chatanywhere.htm> Chat Anywhere is a "powerful
chat server software for real-time chatting. With Chat Anywhere, you can
easily design professional web-based chat rooms. You don't have to know
any computer program language to use this software."
The chat server can be caused to crash by connecting fake users to it.
DETAILS
Vulnerable Systems:
* Chat Anywhere version 2.72a
The chat server is unable to manage fake users. An attacker can crash the
chat server and cause it to consume a lot of CPU resources. The CPU
hogging effect is not limited to the server itself but propagates to all
the real clients connected.
Exploit:
The following proof of concept is available from
<http://www.autistici.org/fdonato/poc/ChatAnywhere[272a]DoS-poc.zip>
http://www.autistici.org/fdonato/poc/ChatAnywhere[272a]DoS-poc.zip.
And from <http://aluigi.altervista.org/poc/chatanydos.zip>
http://aluigi.altervista.org/poc/chatanydos.zip.
Vendor Status:
The bug was initially found on 4 Dec 2003 in the version 2.72, and
reported to the vendor by Luigi Auriemma, but the vendor probably forgot
to fix it. So the vendor was contacted for the same bug in the next
version 2.72a. Now the vendor is planning to fix the bug in the next
release. In the meantime it is recommended to add password protection to
protect the chat room.
ADDITIONAL INFORMATION
The information has been provided by <mailto:fdonato@autistici.org>
Donato Ferrante.
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
- Previous message: SecuriTeam: "[EXPL] Courier-IMAP Remote Format String Vulnerability Exploit"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
- [NT] w3wp DoS
... The following security advisory is sent to the securiteam mailing list, and
can be found at the SecuriTeam web site: http://www.securiteam.com ... 1/12/2006 - Vendor requested
for additional info ... recv(conn_socket, szBuffer, 256, 0); ... (Securiteam) - [NEWS] Everybuddy Vulnerable to a DoS Attack (Long Message)
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... sub Message { ...
After numerous attempts to contact the vendor (in some cases the vendor ... (Securiteam) - [NEWS] HAURI Anti-Virus Directory Traversal
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... * ViRobot Advanced Server
... The vendor has released a patch for ViRobot Linux Server 2.0: ... (Securiteam) - [UNIX] Happymall E-Commerce Input Validation Flaw Lets Remote Users Execute Arbitrary Commands
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... Revin Aldi reported an input
validation vulnerability in the Happymall ... The vendor reports that the 'member_html.cgi'
script is also affected. ... (Securiteam) - [UNIX] Multiple Vendor xzgv PRF Parsing Integer Overflow Vulnerability
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... Remote exploitation of an integer
overflow vulnerability in various ... Vendor Response: ... (Securiteam)