exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

pragmassh-adv.txt

pragmassh-adv.txt
Posted Jan 5, 2008
Authored by Luigi Auriemma | Site aluigi.org

Pragma FortressSSH versions 5.0 Build 4 Revision 293 and below suffer from a denial of service vulnerability.

tags | advisory, denial of service
SHA-256 | 47404a6f184514f51ba1990f501289d9357be57d1719c236cf552bd634c6620a

pragmassh-adv.txt

Change Mirror Download
#######################################################################

Luigi Auriemma

Application: Pragma FortressSSH
http://www.pragmasys.com/FortressSSHServer.asp
Versions: <= 5.0 Build 4 Revision 293
Platforms: Windows
Bug: Denial of Service
Exploitation: remote
Date: 02 Jan 2008
Author: Luigi Auriemma
e-mail: aluigi@autistici.org
web: aluigi.org


#######################################################################


1) Introduction
2) Bug
3) The Code
4) Fix


#######################################################################

===============
1) Introduction
===============


Pragma FortressSSH is a commercial SSH server for Windows.


#######################################################################

======
2) Bug
======


The server, which starts a sshd.exe process for each incoming
connection, uses the secure *_s functions of msvcrt for working on the
incoming strings.
This method allows the avoiding of buffer-overflow vulnerabilities but
the process terminates and shows a message error if an exception
occurs.

An example is the using of a list of keys longer than 4096 which will
raise the exception in vsprintf_s during the building of the formatted
string, while another example is using a long username.

Although the termination of a single process doesn't affect the others,
the access to the server can be denied through the termination of at
least 75 of these processes, after that the server will be unreachable
(all the current SSH connections established before the last exception
will remain up).

This bad effect will finish gradually when the admin clicks on the
error messages (for example if he closes the first dialogbox a new
connection to the server will be possible) but naturally the attacker
can continue the attack keeping the server ever unreacheable.


#######################################################################

===========
3) The Code
===========


http://aluigi.org/poc/pragmassh.zip


#######################################################################

======
4) Fix
======


No fix


#######################################################################
Login or Register to add favorites

File Archive:

October 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Oct 1st
    39 Files
  • 2
    Oct 2nd
    23 Files
  • 3
    Oct 3rd
    18 Files
  • 4
    Oct 4th
    20 Files
  • 5
    Oct 5th
    0 Files
  • 6
    Oct 6th
    0 Files
  • 7
    Oct 7th
    17 Files
  • 8
    Oct 8th
    66 Files
  • 9
    Oct 9th
    25 Files
  • 10
    Oct 10th
    0 Files
  • 11
    Oct 11th
    0 Files
  • 12
    Oct 12th
    0 Files
  • 13
    Oct 13th
    0 Files
  • 14
    Oct 14th
    0 Files
  • 15
    Oct 15th
    0 Files
  • 16
    Oct 16th
    0 Files
  • 17
    Oct 17th
    0 Files
  • 18
    Oct 18th
    0 Files
  • 19
    Oct 19th
    0 Files
  • 20
    Oct 20th
    0 Files
  • 21
    Oct 21st
    0 Files
  • 22
    Oct 22nd
    0 Files
  • 23
    Oct 23rd
    0 Files
  • 24
    Oct 24th
    0 Files
  • 25
    Oct 25th
    0 Files
  • 26
    Oct 26th
    0 Files
  • 27
    Oct 27th
    0 Files
  • 28
    Oct 28th
    0 Files
  • 29
    Oct 29th
    0 Files
  • 30
    Oct 30th
    0 Files
  • 31
    Oct 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close