Subscribe to Windows IT Pro
January 06, 2004 12:00 AM

Denial of Service in GoodTech Systems Telnet Server for Windows

Windows IT Pro
InstantDoc ID #41369
Rating: (0)

Reported January 5, 2004 by Donato Ferrante.

 

 

VERSIONS AFFECTED

 

  • GoodTech Systems Telnet Server 4.0.103

 

DESCRIPTION

 

GoodTech Systems Telnet Server 4.0.103 contains a Denial of Service (DoS) vulnerability. By sending an overly long string as input to the vulnerable server, an attacker can cause the server to stop responding.

 
DEMONSTRATION
 
The discoverer posted the following demonstration as proof of concept:

 

To test the vulnerability, simply send a long string to the Telnet server, perl -e 'print "a"x8245' | nc server 23

Alternatively, a string like :
aaaa\[..a..]aa ( 8245 of a )

 

VENDOR RESPONSE

 

GoodTech Systems has released version 4.0.104, which isn't vulnerable to this condition.

 

CREDIT

 

Discovered by Donato Ferrante.

Related Content:

ARTICLE TOOLS

Comments
    There are no comments to display. Be the first one!
You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.