what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Xitami-2.4d4.dos.txt

Xitami-2.4d4.dos.txt
Posted Feb 29, 2000
Authored by nemesystm | Site dhc1.cjb.net

The Xitami Windows 95/98 webserver is vulnerable to a remote DoS attack.

tags | exploit, remote, denial of service
systems | windows
SHA-256 | 64fd8af32411e699883ac1a9b8fdeeccfc5dc800bea17a82b88105de457d8d4d

Xitami-2.4d4.dos.txt

Change Mirror Download
+++>===] Written by Nemesystm, member of the DHC [===<+++
++++>==] Visit us at dhc1.cjb.net You want 2 [==<++++

Subject: Xitami 2.4d4 win95/98 DoS
Description program: Xitami is a HTTP Server with a FTP daemon, etc.
Description DoS: Simply by connecting and disconnecting to a port Xitami
opens, you can completely lock up the server.

<-[what was used]->
Xitami 2.4d4 for Windows 95/98 downloaded from tucows.com
Installed with the typical installation, no standard settings changed.
This problem worked on: Windows 98 + IE5.0 and Windows NT 4.0 SP5
Xitami 2.4d6 (current version, same settings, not tested in WinNT no problem
in W98)
Xitami 2.5d2 Beta (version to come up, not tested in WinNT no problem W98)

<-[how to create the problem]->
telnet to victim.com 81
or whatever you feel like to connect to port 81.
then just hit enter or disconnect. Either way, on the server side the error
"assertion failed!" shows up, and as long as it's there, no connection whatsoever
can be made to the HTTP service nor the FTP Service nor port 81 (where LWRP
listens on, for a description on what that is, see the documentation that
comes with Xitami)
The message says: "Module E:\IMATIX\DEVELOP\SMT\XILRWP.C, line 265"
You then get three choices: Abort, Retry and Ignore. Retry and Ignore make
it that you can continue without a problem, (even though the server was
unreachable for as long as the error message was there), Abort however kills
the server and gives a Microsoft Visual C++ Runtime error. (abnormal program
termination).

<-[so what]->
This might not seem to be a big problem at first: just check the monitor
every once in a while, but what if you're not working? What if it's weekend?
What if it's at night? There's no telling how many people weren't able to
see the site while you're gone.

<-[logs]->
The logs show nothing spectacular.
console.log in /logs says:
2000/01/14/11:23:45: xilrwp: Peer failed to connect (ERROR: Malformed startup
string)
xitami.log shows something similar.
No IP addresses from the culprit. 8-)

<-[fix]->
Well, I waited with this till the new version was out. The new one doesn't
have the problem, nor does the beta version. I suggest getting that, or
making sure no connections to port 81 are allowed.
It's available at www.imatix.com.

Greetz,
nemesystm, leader of the DHC (dhc1.cjb.net)

>>>The End<<<
auto45040@hushmail.com for questions.

Login or Register to add favorites

File Archive:

May 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    44 Files
  • 2
    May 2nd
    5 Files
  • 3
    May 3rd
    11 Files
  • 4
    May 4th
    0 Files
  • 5
    May 5th
    0 Files
  • 6
    May 6th
    28 Files
  • 7
    May 7th
    3 Files
  • 8
    May 8th
    4 Files
  • 9
    May 9th
    54 Files
  • 10
    May 10th
    12 Files
  • 11
    May 11th
    0 Files
  • 12
    May 12th
    0 Files
  • 13
    May 13th
    17 Files
  • 14
    May 14th
    11 Files
  • 15
    May 15th
    17 Files
  • 16
    May 16th
    13 Files
  • 17
    May 17th
    22 Files
  • 18
    May 18th
    0 Files
  • 19
    May 19th
    0 Files
  • 20
    May 20th
    17 Files
  • 21
    May 21st
    18 Files
  • 22
    May 22nd
    7 Files
  • 23
    May 23rd
    111 Files
  • 24
    May 24th
    27 Files
  • 25
    May 25th
    0 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close