exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

ezboard-scx-sa-03.txt

ezboard-scx-sa-03.txt
Posted May 26, 2000
Authored by Frazzle_Freckle

Securax-SA-03 - Ezboard v5.3.9 remote dos attack via wildcards in URL.

tags | exploit, remote
SHA-256 | ed822a1fc27e53ef490ca1eaffb4b388a0110ab561a1a5b201ae6e3397654cf5

ezboard-scx-sa-03.txt

Change Mirror Download
=============================================================================
Securax-SA-03 Security Advisory
belgian.networking.security Dutch
=============================================================================
Topic: Ezboard ver. 5.3.9 can be caused unreachable.
Announced: 2000-05-24
Affects: Ezboard Ver. 5.3.9.
Other versions not tested.
=============================================================================



Note: This entire advisory has been based upon trial and error results. We
can not ensure the information below is 100% correct being that we have
no source code to audit. This document is subject to change without
prior notice.

If you happen to find more information or problems concerning the below
problem or further varients please contact ezboard themselves and/or
frazzle_freckle@hehe.com.

I. Problem Description
-----------------------

When someone visits http://pub4.ezboard.com/u*.showPublicProfile for example,
every ezboard on server6.ezboard.com will become unreachable for anyone.
The problem occurs when trying to Show a users public profile. When a user
is replaced with '*' it causes the server to strain. If you want to make the
ezboards on pub7.ezboard.com unreachable you can visit the following site as
well: http://pub7.ezboard.com/u*.showPublicProfile. Not much research has
been directed to locating the full list of pub* servers. Variable standard
wildcard characters also cause the servers to have the same reaction, ie: $,
&, @, etc.

II. Impact

Ezboard servers and client message boards, etc. can be caused to be lagged
and unreachable while the service strains for large wildcard responses.
Their could be made code that would take the server down fully.
For example: perl -e 'for(;;){`(sleep 30;killall -9 lynx)|lynx http://address/`}'
This is not tested.

III. Solution

The service has been notified and will hopefully be fixed within the near
future to prevent and further misfortune for current clients/users in action
of service. I would strongly suggest changing the character type of the
standard wildcards which do special uneeded tasks.

IV. Credits

greetz: R00T-dude, securax, Zoa_Chien, Visjnu, Zym0t1c, HTWX, H4H, loophole and hhp.

-Frazzle_Freckle(frazzle_freckle@hehe.com).
=============================================================================
For more information frazzle_freckle@hehe.com
Website http://www.securax.org
Advisories/Text http://www.securax.org/pers
-----------------------------------------------------------------------------
Login or Register to add favorites

File Archive:

August 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    15 Files
  • 2
    Aug 2nd
    22 Files
  • 3
    Aug 3rd
    0 Files
  • 4
    Aug 4th
    0 Files
  • 5
    Aug 5th
    15 Files
  • 6
    Aug 6th
    11 Files
  • 7
    Aug 7th
    43 Files
  • 8
    Aug 8th
    42 Files
  • 9
    Aug 9th
    36 Files
  • 10
    Aug 10th
    0 Files
  • 11
    Aug 11th
    0 Files
  • 12
    Aug 12th
    27 Files
  • 13
    Aug 13th
    0 Files
  • 14
    Aug 14th
    0 Files
  • 15
    Aug 15th
    0 Files
  • 16
    Aug 16th
    0 Files
  • 17
    Aug 17th
    0 Files
  • 18
    Aug 18th
    0 Files
  • 19
    Aug 19th
    0 Files
  • 20
    Aug 20th
    0 Files
  • 21
    Aug 21st
    0 Files
  • 22
    Aug 22nd
    0 Files
  • 23
    Aug 23rd
    0 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    0 Files
  • 27
    Aug 27th
    0 Files
  • 28
    Aug 28th
    0 Files
  • 29
    Aug 29th
    0 Files
  • 30
    Aug 30th
    0 Files
  • 31
    Aug 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close