exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

winshadow.txt

winshadow.txt
Posted Oct 1, 2003
Authored by Bahaa Naamnmeh | Site bsecurity.tk

OmniCon WinShadow version 2.0 suffers from a buffer overflow in the client handling of hostnames in host files. A denial of service also exists whenever an excessively long username or password is used.

tags | advisory, denial of service, overflow
SHA-256 | 1ab3f35a2cae652c184347381e282940b2819ed0fa2fd143dfdca37f01511eb9

winshadow.txt

Change Mirror Download
Multiple vulnerabilities in WinShadow
-------------------------------------


Affected Systems: OmniCom WinShadow

version: 2.0 (and possibly earlier versions)

Vendor: OmniCom Technologies - http://www.omnicomtech.com

Issue: 1. Buffer overflow in client handling hostnames in host files
2. DoS against server

Released: 27 September 2003


Introduction:
=============
"winshdow: Create a secure remote control session on the Internet or private WAN/LAN network allowing easy access to remote files and applications. Increase productivity by allowing secure remote access for mobile users and system administrators."

- Vendors Description
[ http://www.omnicomtech.com ]


Details:
========
Multiple vulnerabilities has been identified in winShadow version 2.0, which allows malicious users to execute arbitrary code on the master client and remotely crash the server.

Buffer Overflow:
----------------
winShadow saves hostnames in host files (*.osh), the process handing the hostname parameter read from the file will cause a buffer overflow if approximately 250 bytes are passed after this parameter.

Denial of Service:
------------------
By connecting to the server and issuing a long username or password, the server will crash, refusing any further connections until the server is closed by logging off or rebooting the system, this may be because it a service that runs with system privileges.


Vendor status:
==============
The vendor has been informed.


Exploit:
========
Can be downloaded from http://www.elitehaven.net/winshadow.zip
The exploit was written by Peter Winter-Smith.


Discovered by/Credit:
=====================
Bahaa Naamneh
b_naamneh@hotmail.com
http://www.bsecurity.tk
Login or Register to add favorites

File Archive:

August 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    15 Files
  • 2
    Aug 2nd
    22 Files
  • 3
    Aug 3rd
    0 Files
  • 4
    Aug 4th
    0 Files
  • 5
    Aug 5th
    15 Files
  • 6
    Aug 6th
    11 Files
  • 7
    Aug 7th
    43 Files
  • 8
    Aug 8th
    42 Files
  • 9
    Aug 9th
    36 Files
  • 10
    Aug 10th
    0 Files
  • 11
    Aug 11th
    0 Files
  • 12
    Aug 12th
    27 Files
  • 13
    Aug 13th
    0 Files
  • 14
    Aug 14th
    0 Files
  • 15
    Aug 15th
    0 Files
  • 16
    Aug 16th
    0 Files
  • 17
    Aug 17th
    0 Files
  • 18
    Aug 18th
    0 Files
  • 19
    Aug 19th
    0 Files
  • 20
    Aug 20th
    0 Files
  • 21
    Aug 21st
    0 Files
  • 22
    Aug 22nd
    0 Files
  • 23
    Aug 23rd
    0 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    0 Files
  • 27
    Aug 27th
    0 Files
  • 28
    Aug 28th
    0 Files
  • 29
    Aug 29th
    0 Files
  • 30
    Aug 30th
    0 Files
  • 31
    Aug 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close