Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Vulnerability Development: Re: ADV: /con/con is yet exploitable on most fservs

Re: ADV: /con/con is yet exploitable on most fservs

From: Cam <canasta_at_ONE.NET.AU>
Date: Thu, 8 Jun 2000 17:29:24 +1000

This bug has been covered before. It's an old Microsoft problem of the MS
DOS days. Certain devices were reserved like COM1, CON and LPT1. I spoke
to the author of mIRC regarding the issue some time ago and, yes any
Windows/NT-based boxen will suffer the problem unless patched. MS does
offer the patch. If you are on IRC and are not patched, you can be
disconnected via CTCP notices with '/con/con' for example in it. A common
way for lamers to use the bug is to play a WAV file in a channel. The WAV
file is named con/con.wav. Then they watch the unpatched ppl fall.
Hope this helps.

Cam

Paulo Ribeiro wrote:

> The /dev/dev Win9x bug can be exploited on fservs at IRC. If you access
> the fserv and try:
>
> <hee> fserv...
> <you> get /con/con
>
> You may receive: hee has quit (Connection reset by peer) or <hee>
> Invalid filename (or something like this). So, you may try: <you> get
> /lpt1/lpt1/lpt1/lpt1/lpt1/lpt1/lpt1/lpt1/con/con
>
> And you shall receive: hee has quit (Connection reset by peer)
>
> Yours,
> Paulo Ribeiro.
Received on Jun 08 2000

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos