exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

chatman151.txt

chatman151.txt
Posted Oct 1, 2004
Authored by Luigi Auriemma | Site aluigi.altervista.org

Improper memory allocation in Chatman versions 1.5.1 RC1 and below leave it susceptible to a denial of service attack.

tags | advisory, denial of service
SHA-256 | 6cace12445dcff93c2b73587c5ab07e74fd98329b84515bd066931ce3e7d820a

chatman151.txt

Change Mirror Download

#######################################################################

Luigi Auriemma

Application: Chatman
http://www.vp-soft.com/software/chatman.php
Versions: <= 1.5.1 RC1
Platforms: Windows
Bug: crash
Risk: medium
Exploitation: remote, broadcast
Date: 27 September 2004
Author: Luigi Auriemma
e-mail: aluigi@altervista.org
web: http://aluigi.altervista.org


#######################################################################


1) Introduction
2) Bug
3) The Code
4) Fix


#######################################################################

===============
1) Introduction
===============


Chatman is an intranet application combining chat (in IRC style), files
transfer and some games.


#######################################################################

======
2) Bug
======


Each data block exchanged by Chatman is constituited by a 32 bits
number used to identify the data size.

The amount of memory specified by this number is immediately allocated
but if it is too big (and so allocation fails) the program terminates
automatically.

Also if the program uses the TCP protocol is possible to crash any
Chatman host in the LAN simply sending a "new user" broadcast packet,
they will automatically connect to the attacker that can passively
exploit the bug as described previously.


#######################################################################

===========
3) The Code
===========


http://aluigi.altervista.org/poc/chatmanx.zip


#######################################################################

======
4) Fix
======


No fix.
Chatman is no longer supported.


#######################################################################


---
Luigi Auriemma
http://aluigi.altervista.org

Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close