exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

defcom.imagecast.txt

defcom.imagecast.txt
Posted Jan 9, 2001
Authored by Defcom Labs | Site defcom.com

Defcom Labs Advisory def-2001-01 - ImageCast V4.1.0 for Windows, a rapid-PC-deployment tool much like Ghost, has problems handling malformed input which result in a dos attack against the ImageCast Control Center.

tags | exploit
systems | windows
SHA-256 | 39f8a768d3f4a48a511b385ecf3c598de70d7bb5bec3da86c6b00e75380a0698

defcom.imagecast.txt

Change Mirror Download
======================================================================
Defcom Labs Advisory def-2001-01

ImageCast IC3 Control Center DoS

Author: Peter Gründl <peter.grundl@defcom.com>
Release Date: 2001-01-08
======================================================================
------------------------=[Brief Description]=-------------------------
ImageCast, a rapid-PC-deployment tool, much like Ghost, has problems
handling malformed input. These problems can result in a DoS against
the ImageCast Control Center.

------------------------=[Affected Systems]=--------------------------
- ImageCast V4.1.0

----------------------=[Detailed Description]=------------------------
Sending a string of approx. 50Kb to the ICCC service (TCP port 12002)
results in the server consuming all available CPU and no longer
accepting connections to that port.

Sending multiple packets to port 8081 starting from size 14000 bytes
(+carriage return & linefeed), results in a warning box being opened
for each connection, and will eventually (after approx 326 packets)
result in the OS killing ICCC.exe within a very short time.

---------------------------=[Workaround]=-----------------------------
None known. The vendor, Storagesoft Inc., can be contacted through
their website at http://www.storagesoft.com/corporate/contact.asp.
Please refer to the incident number ([Incident:main 001222-0002]),
if you contact Storagesoft regarding this issue.

-------------------------=[Vendor Response]=--------------------------
This issue was brought to the vendor's attention on the 21st of
December and assigned incident number [Incident:main 001222-0002].
Three emails were exchanged and here is a snippet from the
correspondance:

"At 12/29/2000 02:16 PM we wrote - Peter, this is an issue that will
be dealt with in a future version of Imagecast. The information you
have provided has been forwarded to the product manager. It has been
closed so it is no longer in the tech support database since it is
an issue that can currently only be fixed through code changes in
the program."

Attempts to find out which version this would be, and when it would
be released, resulted in this reply:

"At 01/04/2001 03:30 PM we wrote - We currently do not have the data
as to which version it will be done with. We will most likely be
unable to provide that information until a the very least 1 to 2
weeks before a release. We cannot release a product with out
testing for specifics. At the very least we are trying to get more
time to test before release dates."

======================================================================
This release was brought to you by Defcom Labs

labs@defcom.com www.defcom.com
======================================================================



Login or Register to add favorites

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    27 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    1 Files
  • 9
    Sep 9th
    16 Files
  • 10
    Sep 10th
    38 Files
  • 11
    Sep 11th
    21 Files
  • 12
    Sep 12th
    40 Files
  • 13
    Sep 13th
    18 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    21 Files
  • 17
    Sep 17th
    51 Files
  • 18
    Sep 18th
    23 Files
  • 19
    Sep 19th
    48 Files
  • 20
    Sep 20th
    0 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close