EH-Net
May 22, 2013, 01:31:27 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Denial of Service  (Read 7053 times)
0 Members and 1 Guest are viewing this topic.
Inc0
Newbie
*
Offline Offline

Posts: 2


View Profile
« on: July 02, 2011, 02:05:01 PM »

Hello, I need some explanation, check this exploit : http://1337day.com/exploits/14229, its a denial of service, but how can I dos someone with this ?

Thank You Cheesy
Logged
cd1zz
Hero Member
*****
Offline Offline

Posts: 561


View Profile WWW
« Reply #1 on: July 02, 2011, 03:01:55 PM »

Its not a remote exploit so you would have to convince someone to open your .m3u or .pls file.
Logged

Data_Raid
Full Member
***
Offline Offline

Posts: 165



View Profile
« Reply #2 on: July 02, 2011, 03:14:39 PM »

Hello, I need some explanation, check this exploit : http://1337day.com/exploits/14229, its a denial of service, but how can I dos someone with this ?

Thank You Cheesy

The exploit mentions that BS Player 2.56  needs to be installed (might also work on the latest version: 2.57), the "victim" needs to open the crafted playlist file (m3u or pls). So you will need to send someone your malicious playlist file (hosting the playlist on a website might also work), all the exploit does is write 25000 A's and crash the app.
Logged

All men by nature desire knowledge.

Aristotle
cd1zz
Hero Member
*****
Offline Offline

Posts: 561


View Profile WWW
« Reply #3 on: July 02, 2011, 06:47:30 PM »

A better exercise would be to complete the exploit. It's unicode but c0relan has some great references for this Smiley
Logged

Inc0
Newbie
*
Offline Offline

Posts: 2


View Profile
« Reply #4 on: July 02, 2011, 11:22:43 PM »

Thank you all, I have one more question, whats the difference, between this : http://www.exploit-db.com/exploits/11839/ (Local Crash) and that (Denial of serice) exploit ?
Logged
cd1zz
Hero Member
*****
Offline Offline

Posts: 561


View Profile WWW
« Reply #5 on: July 03, 2011, 09:06:25 AM »

A denial of service and a crash are the same thing. The terms are often used interchangeably. A PoC (noted in your exploit-db example) is a "proof of concept." In both of the examples you've asked about, a researcher found the bug but did not finish the exploit to show how to get code execution. Not all bugs are exploitable which is why they might of stopped here. There is only one way to find out!
Logged

Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines Valid XHTML 1.0! Valid CSS!
Page created in 0.086 seconds with 20 queries.