OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Dave Aitel (dave_at_immunitysec.com)
Date: Tue Oct 01 2002 - 10:18:36 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    For those of you who have a desire to crash Microsoft's PPTP stack, I
    have a pptp .spk script linked off of
    http://www.immunitysec.com/spike.html.

    It would probably be good to run against other PPTP stacks as well.
    (Likewise, SPIKE's msrpcfuzzer takes down free software dce-rpc stacks
    just as fast as it takes down the non-free stacks.)

    It's not a bad demonstration of how to use SPIKE scripts either, if
    you're inclined to learn. Finding this bug took less than thirty
    minutes...(</marketing>)

    To run it:
    # first enable the shared library fun
    bash$ . ./ls.sh
    # now run the script against 192.168.1.100 after setting up PPTP on that
    machine. It's a good idea to set up SoftIce as well.
    bash$ ./generic_send_tcp 192.168.1.100 1723 ./pptp.spk 0 0
    #wait for crash. It's in the second packet, I believe.

    Dave Aitel
    Immunity, Inc.

    References
    -----------------------------

       [1] phion Information Technologies
           http://www.phion.com/

    Exploit
    -----------------------------

       phion Information Technologies will not provide an exploit for this
    issue.

    :>

    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.0.6 (GNU/Linux)
    Comment: For info see http://www.gnupg.org

    iD8DBQA9mbzMB8JNm+PA+iURAgqcAKCIm4Ur3xBqFUtNBqileJTqBH39NACfWHyn
    IL5mQok/ErYRLZ6kcf4oXY8=
    =Ac/p
    -----END PGP SIGNATURE-----