vendor:
LinkLogger
by:
Mike Cyr (h00die)
7,5
CVSS
HIGH
Denial of Service (DoS)
N/A
CWE
Product Name: LinkLogger
Affected Version From: 2.4.10.15
Affected Version To: 2.4.10.15
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
LinkLogger 2.4.10.15 syslog DoS
This exploit is a Denial of Service (DoS) attack against LinkLogger 2.4.10.15. It sends 20,000 packets to the destination IP from a spoofed source IP, which overwhelms the program and shuts down the port. The exploit was coded by Mike Cyr, aka h00die, and was tested against 2.4.10.15. Vendor notification was sent on 4/13/09, and vendor acknowledgement was received on 4/14/09. Vendor was unable to run the DoS code successfully on 5/11/09, and instructions and a video on how to install all needed modules and run the exploit successfully were sent on 5/12/09. The exploit was sent to milw0rm and security focus on 6/13/09.
Mitigation:
The vendor has not released a patch for this vulnerability.