CVE-2002-1024
published 2002-10-04CVE-2002-1024: Cisco IOS 12.0 through 12.2, when supporting SSH, allows remote attackers to cause a denial of service (CPU consumption) via a large packet that was designed…
PriorityP419high7.1CVSS 2.0
AVNACMAuNCNINAC
EPSS
3.30%
87.1th percentile
Cisco IOS 12.0 through 12.2, when supporting SSH, allows remote attackers to cause a denial of service (CPU consumption) via a large packet that was designed to exploit the SSH CRC32 attack detection overflow (CVE-2001-0144).
Affected
104 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | catos | — | — |
| cisco | catos | — | — |
| cisco | catos | — | — |
| cisco | catos | — | — |
| cisco | catos | — | — |
| cisco | catos | — | — |
| cisco | catos | — | — |
| cisco | catos | — | — |
| cisco | catos | — | — |
| cisco | catos | — | — |
| cisco | catos | — | — |
| cisco | catos | — | — |
| cisco | catos | — | — |
| cisco | catos | — | — |
| cisco | catos | — | — |
| cisco | catos | — | — |
| cisco | catos | — | — |
| cisco | catos | — | — |
| cisco | catos | — | — |
| cisco | catos | — | — |
| cisco | catos | — | — |
| cisco | catos | — | — |
| cisco | catos | — | — |
| cisco | catos | — | — |
| cisco | catos | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mw6p-g59x-wqvw: Unspecified vulnerability in SSHield 1
ghsa_unreviewed·2022-05-01·CVSS 10.0
CVE-2007-4654 [CRITICAL] GHSA-mw6p-g59x-wqvw: Unspecified vulnerability in SSHield 1
Unspecified vulnerability in SSHield 1.6.1 with OpenSSH 3.0.2p1 on Cisco WebNS 8.20.0.1 on Cisco Content Services Switch (CSS) series 11000 devices allows remote attackers to cause a denial of service (connection slot exhaustion and device crash) via a series of large packets designed to exploit the SSH CRC32 attack detection overflow (CVE-2001-0144), possibly a related issue to CVE-2002-1024.
GHSA
GHSA-98x9-358f-pg9v: Cisco IOS 12
ghsa_unreviewed·2022-04-30·CVSS 10.0
CVE-2002-1024 [CRITICAL] GHSA-98x9-358f-pg9v: Cisco IOS 12
Cisco IOS 12.0 through 12.2, when supporting SSH, allows remote attackers to cause a denial of service (CPU consumption) via a large packet that was designed to exploit the SSH CRC32 attack detection overflow (CVE-2001-0144).
Suricata
GPL NETBIOS SMB IrotIsRunning attempt
suricata·2010-09-23
CVE-2002-1561 GPL NETBIOS SMB IrotIsRunning attempt
GPL NETBIOS SMB IrotIsRunning attempt
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET 139 (msg:"GPL NETBIOS SMB IrotIsRunning attempt"; flow:established,to_server; flowbits:isset,smb.tree.bind.irot; content:"|00|"; depth:1; content:"|FF|SMB%"; within:5; distance:3; byte_test:1,!&,128,6,relative; content:"&|00|"; within:2; distance:56; content:"|5C|PIPE|5C 00|"; distance:4; nocase; byte_jump:2,-17,relative,from_beginning,little; isdataat:4,relative; content:"|05|"; byte_test:1,!&,16,3,relative; content:"|00|"; within:1; distance:1; content:"|00 02|"; within:2; distance:19; byte_jump:4,8,relative,little,align; byte_test:4,>,1024,0,little; reference:bugtraq,6005; reference:cve,2002-1561; reference:url,www.microsoft.com/technet/security/bulletin/MS03-010.mspx; classtype:protocol-command-decode
Suricata
GPL NETBIOS SMB-DS IrotIsRunning attempt
suricata·2010-09-23
CVE-2002-1561 GPL NETBIOS SMB-DS IrotIsRunning attempt
GPL NETBIOS SMB-DS IrotIsRunning attempt
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET 445 (msg:"GPL NETBIOS SMB-DS IrotIsRunning attempt"; flow:established,to_server; flowbits:isset,smb.tree.bind.irot; content:"|00|"; depth:1; content:"|FF|SMB%"; within:5; distance:3; byte_test:1,!&,128,6,relative; content:"&|00|"; within:2; distance:56; content:"|5C|PIPE|5C 00|"; distance:4; nocase; byte_jump:2,-17,relative,from_beginning,little; isdataat:4,relative; content:"|05|"; byte_test:1,!&,16,3,relative; content:"|00|"; within:1; distance:1; content:"|00 02|"; within:2; distance:19; byte_jump:4,8,relative,little,align; byte_test:4,>,1024,0,little; reference:bugtraq,6005; reference:cve,2002-1561; reference:url,www.microsoft.com/technet/security/bulletin/MS03-010.mspx; classtype:protocol-command-
Suricata
GPL NETBIOS SMB-DS IrotIsRunning little endian andx attempt
suricata·2010-09-23
CVE-2002-1561 GPL NETBIOS SMB-DS IrotIsRunning little endian andx attempt
GPL NETBIOS SMB-DS IrotIsRunning little endian andx attempt
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET 445 (msg:"GPL NETBIOS SMB-DS IrotIsRunning little endian andx attempt"; flow:established,to_server; flowbits:isset,smb.tree.bind.irot; content:"|00|"; depth:1; content:"|FF|SMB"; within:4; distance:3; pcre:"/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR"; byte_test:1,!&,128,6,relative; content:"%"; depth:1; offset:39; byte_jump:2,0,little,relative; content:"&|00|"; within:2; distance:29; content:"|5C|PIPE|5C 00|"; distance:4; nocase; byte_jump:2,-17,relative,from_beginning,little; isdataat:4,relative; content:"|05|"; byte_test:1,&,16,3,relative; content:"|00|"; within:1; distance:1; content:"|02 00|"; within:2; distance:19; byte_jump:4,8,relative,little,align; byte_test:4,>,1024,0,li
Suricata
GPL NETBIOS SMB-DS IrotIsRunning andx attempt
suricata·2010-09-23
CVE-2002-1561 GPL NETBIOS SMB-DS IrotIsRunning andx attempt
GPL NETBIOS SMB-DS IrotIsRunning andx attempt
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET 445 (msg:"GPL NETBIOS SMB-DS IrotIsRunning andx attempt"; flow:established,to_server; flowbits:isset,smb.tree.bind.irot; content:"|00|"; depth:1; content:"|FF|SMB"; within:4; distance:3; pcre:"/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR"; byte_test:1,!&,128,6,relative; content:"%"; depth:1; offset:39; byte_jump:2,0,little,relative; content:"&|00|"; within:2; distance:29; content:"|5C|PIPE|5C 00|"; distance:4; nocase; byte_jump:2,-17,relative,from_beginning,little; isdataat:4,relative; content:"|05|"; byte_test:1,!&,16,3,relative; content:"|00|"; within:1; distance:1; content:"|00 02|"; within:2; distance:19; byte_jump:4,8,relative,little,align; byte_test:4,>,1024,0,little; reference:bugtraq,600
Suricata
GPL NETBIOS SMB IrotIsRunning unicode little endian attempt
suricata·2010-09-23
CVE-2002-1561 GPL NETBIOS SMB IrotIsRunning unicode little endian attempt
GPL NETBIOS SMB IrotIsRunning unicode little endian attempt
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET 139 (msg:"GPL NETBIOS SMB IrotIsRunning unicode little endian attempt"; flow:established,to_server; flowbits:isset,smb.tree.bind.irot; content:"|00|"; depth:1; content:"|FF|SMB%"; within:5; distance:3; byte_test:1,&,128,6,relative; content:"&|00|"; within:2; distance:56; content:"|5C 00|P|00|I|00|P|00|E|00 5C 00 00 00|"; distance:4; nocase; byte_jump:2,-17,relative,from_beginning,little; isdataat:4,relative; content:"|05|"; byte_test:1,&,16,3,relative; content:"|00|"; within:1; distance:1; content:"|02 00|"; within:2; distance:19; byte_jump:4,8,relative,little,align; byte_test:4,>,1024,0,little; reference:bugtraq,6005; reference:cve,2002-1561; reference:url,www.microsoft.com/technet/
Suricata
GPL NETBIOS SMB-DS IrotIsRunning unicode attempt
suricata·2010-09-23
CVE-2002-1561 GPL NETBIOS SMB-DS IrotIsRunning unicode attempt
GPL NETBIOS SMB-DS IrotIsRunning unicode attempt
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET 445 (msg:"GPL NETBIOS SMB-DS IrotIsRunning unicode attempt"; flow:established,to_server; flowbits:isset,smb.tree.bind.irot; content:"|00|"; depth:1; content:"|FF|SMB%"; within:5; distance:3; byte_test:1,&,128,6,relative; content:"&|00|"; within:2; distance:56; content:"|5C 00|P|00|I|00|P|00|E|00 5C 00 00 00|"; distance:4; nocase; byte_jump:2,-17,relative,from_beginning,little; isdataat:4,relative; content:"|05|"; byte_test:1,!&,16,3,relative; content:"|00|"; within:1; distance:1; content:"|00 02|"; within:2; distance:19; byte_jump:4,8,relative,little,align; byte_test:4,>,1024,0,little; reference:bugtraq,6005; reference:cve,2002-1561; reference:url,www.microsoft.com/technet/security/bulletin/MS0
Suricata
GPL NETBIOS SMB-DS IrotIsRunning little endian attempt
suricata·2010-09-23
CVE-2002-1561 GPL NETBIOS SMB-DS IrotIsRunning little endian attempt
GPL NETBIOS SMB-DS IrotIsRunning little endian attempt
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET 445 (msg:"GPL NETBIOS SMB-DS IrotIsRunning little endian attempt"; flow:established,to_server; flowbits:isset,smb.tree.bind.irot; content:"|00|"; depth:1; content:"|FF|SMB%"; within:5; distance:3; byte_test:1,!&,128,6,relative; content:"&|00|"; within:2; distance:56; content:"|5C|PIPE|5C 00|"; distance:4; nocase; byte_jump:2,-17,relative,from_beginning,little; isdataat:4,relative; content:"|05|"; byte_test:1,&,16,3,relative; content:"|00|"; within:1; distance:1; content:"|02 00|"; within:2; distance:19; byte_jump:4,8,relative,little,align; byte_test:4,>,1024,0,little; reference:bugtraq,6005; reference:cve,2002-1561; reference:url,www.microsoft.com/technet/security/bulletin/MS03-010.mspx;
Suricata
GPL NETBIOS SMB IrotIsRunning little endian attempt
suricata·2010-09-23
CVE-2002-1561 GPL NETBIOS SMB IrotIsRunning little endian attempt
GPL NETBIOS SMB IrotIsRunning little endian attempt
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET 139 (msg:"GPL NETBIOS SMB IrotIsRunning little endian attempt"; flow:established,to_server; flowbits:isset,smb.tree.bind.irot; content:"|00|"; depth:1; content:"|FF|SMB%"; within:5; distance:3; byte_test:1,!&,128,6,relative; content:"&|00|"; within:2; distance:56; content:"|5C|PIPE|5C 00|"; distance:4; nocase; byte_jump:2,-17,relative,from_beginning,little; isdataat:4,relative; content:"|05|"; byte_test:1,&,16,3,relative; content:"|00|"; within:1; distance:1; content:"|02 00|"; within:2; distance:19; byte_jump:4,8,relative,little,align; byte_test:4,>,1024,0,little; reference:bugtraq,6005; reference:cve,2002-1561; reference:url,www.microsoft.com/technet/security/bulletin/MS03-010.mspx; classt
Suricata
GPL NETBIOS SMB IrotIsRunning andx attempt
suricata·2010-09-23
CVE-2002-1561 GPL NETBIOS SMB IrotIsRunning andx attempt
GPL NETBIOS SMB IrotIsRunning andx attempt
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET 139 (msg:"GPL NETBIOS SMB IrotIsRunning andx attempt"; flow:established,to_server; flowbits:isset,smb.tree.bind.irot; content:"|00|"; depth:1; content:"|FF|SMB"; within:4; distance:3; pcre:"/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR"; byte_test:1,!&,128,6,relative; content:"%"; depth:1; offset:39; byte_jump:2,0,little,relative; content:"&|00|"; within:2; distance:29; content:"|5C|PIPE|5C 00|"; distance:4; nocase; byte_jump:2,-17,relative,from_beginning,little; isdataat:4,relative; content:"|05|"; byte_test:1,!&,16,3,relative; content:"|00|"; within:1; distance:1; content:"|00 02|"; within:2; distance:19; byte_jump:4,8,relative,little,align; byte_test:4,>,1024,0,little; reference:bugtraq,6005; ref
Suricata
GPL NETBIOS SMB IrotIsRunning unicode attempt
suricata·2010-09-23
CVE-2002-1561 GPL NETBIOS SMB IrotIsRunning unicode attempt
GPL NETBIOS SMB IrotIsRunning unicode attempt
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET 139 (msg:"GPL NETBIOS SMB IrotIsRunning unicode attempt"; flow:established,to_server; flowbits:isset,smb.tree.bind.irot; content:"|00|"; depth:1; content:"|FF|SMB%"; within:5; distance:3; byte_test:1,&,128,6,relative; content:"&|00|"; within:2; distance:56; content:"|5C 00|P|00|I|00|P|00|E|00 5C 00 00 00|"; distance:4; nocase; byte_jump:2,-17,relative,from_beginning,little; isdataat:4,relative; content:"|05|"; byte_test:1,!&,16,3,relative; content:"|00|"; within:1; distance:1; content:"|00 02|"; within:2; distance:19; byte_jump:4,8,relative,little,align; byte_test:4,>,1024,0,little; reference:bugtraq,6005; reference:cve,2002-1561; reference:url,www.microsoft.com/technet/security/bulletin/MS03-010.
Suricata
GPL NETBIOS SMB-DS IrotIsRunning unicode little endian attempt
suricata·2010-09-23
CVE-2002-1561 GPL NETBIOS SMB-DS IrotIsRunning unicode little endian attempt
GPL NETBIOS SMB-DS IrotIsRunning unicode little endian attempt
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET 445 (msg:"GPL NETBIOS SMB-DS IrotIsRunning unicode little endian attempt"; flow:established,to_server; flowbits:isset,smb.tree.bind.irot; content:"|00|"; depth:1; content:"|FF|SMB%"; within:5; distance:3; byte_test:1,&,128,6,relative; content:"&|00|"; within:2; distance:56; content:"|5C 00|P|00|I|00|P|00|E|00 5C 00 00 00|"; distance:4; nocase; byte_jump:2,-17,relative,from_beginning,little; isdataat:4,relative; content:"|05|"; byte_test:1,&,16,3,relative; content:"|00|"; within:1; distance:1; content:"|02 00|"; within:2; distance:19; byte_jump:4,8,relative,little,align; byte_test:4,>,1024,0,little; reference:bugtraq,6005; reference:cve,2002-1561; reference:url,www.microsoft.com/te
Suricata
GPL NETBIOS SMB IrotIsRunning little endian andx attempt
suricata·2010-09-23
CVE-2002-1561 GPL NETBIOS SMB IrotIsRunning little endian andx attempt
GPL NETBIOS SMB IrotIsRunning little endian andx attempt
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET 139 (msg:"GPL NETBIOS SMB IrotIsRunning little endian andx attempt"; flow:established,to_server; flowbits:isset,smb.tree.bind.irot; content:"|00|"; depth:1; content:"|FF|SMB"; within:4; distance:3; pcre:"/^(\x75|\x2d|\x2f|\x73|\xa2|\x2e|\x24|\x74)/sR"; byte_test:1,!&,128,6,relative; content:"%"; depth:1; offset:39; byte_jump:2,0,little,relative; content:"&|00|"; within:2; distance:29; content:"|5C|PIPE|5C 00|"; distance:4; nocase; byte_jump:2,-17,relative,from_beginning,little; isdataat:4,relative; content:"|05|"; byte_test:1,&,16,3,relative; content:"|00|"; within:1; distance:1; content:"|02 00|"; within:2; distance:19; byte_jump:4,8,relative,little,align; byte_test:4,>,1024,0,little;
Exploit-DB
PlanetWeb 1.14 - GET Buffer Overflow
exploitdb·2002-09-16
CVE-2002-1489 PlanetWeb 1.14 - GET Buffer Overflow
PlanetWeb 1.14 - GET Buffer Overflow
---
source: https://www.securityfocus.com/bid/5710/info
PlanetWeb is a commercially available web server distributed by PlanetDNS. It is available for the Microsoft Windows platform.
PlanetWeb is vulnerable to a buffer overflow condition when handling GET requests of excessive length. Upon receiving a GET request containing a 1024 byte or greater URL, an exploitable buffer overflow occurs.
This may result in the remote execution of arbitrary code within the context of the web server process.
#!/usr/bin/perl
# PlanetWeb Software perl exploit
# by UkR-XblP / UkR security team
use IO::Socket;
unless (@ARGV == 1) { die "usage: $0 vulnurable_server
..." }
$host = shift(@ARGV);
$remote = IO::Socket::INET->new( Proto => "tcp",
PeerAddr => $host,
PeerPort
Exploit-DB
psyBNC 2.3 - Denial of Service
exploitdb·2002-05-19
CVE-2002-0741 psyBNC 2.3 - Denial of Service
psyBNC 2.3 - Denial of Service
---
/*
* psyBNC
#include
#include
#include
#include
#include
#include
#include
#include
#include
#define SIZE 9000
#define PORT 31337
#define USER "pr0ix"
int senddos(int port, int size, char *target, char *user);
int checkvuln(char *rxbuf);
int testvuln(int port, char *target);
unsigned long resolvenametoip(char *name);
void usage(char *prog);
int checked = 0;
int force;
int main(int argc, char *argv[])
{
int c, i, z;
int port, size, times;
int u_t = 0, d_t = 0, n_t = 0, p_t = 0, s_t = 0, t_t;
char target[1024], *user;
printf("[+] ES psyBNC 0) {
vuln_t = 1;
}
if ((int)(bnc[8] - '0') h_addr);
}
return addr;
}
void usage(char *prog)
{
printf("usage: %s [options]\n", prog);
printf("\t-d Server hosting psybnc [REQUIRED]\n");
printf("\t-f force Skip vuln
No writeups or analysis indexed.
http://www.cisco.com/warp/public/707/SSH-scanning.shtmlhttp://www.iss.net/security_center/static/9437.phphttp://www.kb.cert.org/vuls/id/290140http://www.securityfocus.com/bid/5114http://www.cisco.com/warp/public/707/SSH-scanning.shtmlhttp://www.iss.net/security_center/static/9437.phphttp://www.kb.cert.org/vuls/id/290140http://www.securityfocus.com/bid/5114
2002-10-04
Published