Infinite InterChange Vulnerable to Denial of Service (DoS) Attack

InterChange can be crashed by sending simple PUT commands.

Steve Manzuik

December 20, 2000

1 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported December 21 by Strumpf Noir Security

VERSIONS AFFECTED

DESCRIPTIONA Denial of Service (DoS) attack has been discovered that affects Infinite InterChange 3.61. A malicious user can send a malformed POST request and cause the HTTP services to stop responding.

DEMONSTRATION

The attack can be carried out as follows;

Telnet POST aaa(x963+ bytes) HTTP/1.0

The server will stop responding and require a reboot.

VENDOR RESPONSE

Strumpf Noir has notified the vendor.

CREDITDiscovered by Strumpf Noir Security

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like