vendor:
PsyBNC
by:
DVDMAN
7.5
CVSS
HIGH
Denial of Service (DoS)
400
CWE
Product Name: PsyBNC
Affected Version From: 2.3
Affected Version To: 2.3
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: UNIX, Linux
2002
PsyBNC 2.3 Remote DDOS POC
A remote user can crash a vulnerable PsyBNC server by sending a password of 9000 or more characters and disconnecting from the system. This will cause the server process to not die, but instead continue to live and consume a large amount of resources.
Mitigation:
Ensure that the server is running the latest version of PsyBNC and that all passwords are of a reasonable length.