/* * WinME/XP UPNP dos & overflow * * Run: ./XPloit host <option> * * Windows run the "Universal Plug and Play technology" service * at port 5000. In the future this will allow for seemless * connectivity of various devices such as a printer. * This service have a DoS and a buffer overflow I exploit here. * * PD: the -e option spawns a cmd.exe shell on port 7788 coded by isno * * Author: Gabriel Maggiotti * Email: gmaggiot@ciudad.com.ar * Webpage: http://qb0x.net */
int main(int argc,char *argv[]) { int sockfd[MAX]; char sendXP[]="XP"; char jmpcode[281], execode[840],request[2048]; char *send_buffer; int num_socks; int bindport; int i; int port;
This is not new ... the DoS works nice = Blue screen of ...
but i coudn`t get any shell on any port on my lab....
pita
Nov 23 2003, 08:22 PM
Microsoft UPnP NOTIFY Buffer Overflow Vulnerability
bugtraq id 3723 object class Boundary Condition Error cve CVE-2001-0876
remote Yes local No published Dec 20, 2001 updated Nov 19, 2003 vulnerable Microsoft Windows 98 Microsoft Windows 98SE Microsoft Windows ME Microsoft Windows XP Home Microsoft Windows XP Professional
so its seem to be 2 year old but why this vulnerability was updated?
WeeDMoNKeY
Nov 23 2003, 11:54 PM
this is compiled in teh download section.
vnet576
Nov 24 2003, 12:21 AM
Hehe...about every 2 months or so on this board someone makes a post about the amazing "new" UPNP vulnerability. Everyone gets excited, starts compiling it, then realizes that its old and doesn't work...then the cycle repeats itself.
If u don't believe me search for UPNP in the forum and u'll see what i mean.
WeeDMoNKeY
Nov 24 2003, 12:39 AM
this one isnt to old it got "updated" except the fact that it doesnt work worth shit ;D well the dos supposidly works, meh. some guy in the download section said he got 154 machines locally... i havent tried locally, but ive tried remote and its been a fail.
gogu258
Nov 24 2003, 04:14 AM
It doesn't work anyway.
tribalgoa
Nov 24 2003, 09:59 PM
when will ppl finally realise this sploit only works if your on the same segment
GhostCow
Nov 26 2003, 08:57 PM
please explain what you mean to us measly fools triablgoa
yuliang11
Nov 27 2003, 01:12 AM
hmnnn ... didn't work on me
vertygo
Nov 30 2003, 11:55 PM
Not working 2 old i think
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.