MSFN Forum: BNBT BitTorrent Tracker Denial Of Service - MSFN Forum

Jump to content



Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

BNBT BitTorrent Tracker Denial Of Service Rate Topic: -----

#1 User is offline   utln 

  • I loveded you Piggy!
  • PipPipPip
  • Group: Members
  • Posts: 358
  • Joined: 25-November 03

Posted 21 May 2004 - 09:07 PM

The following was taken from a Full Disclosure posting by badpack3t,


SP Research Labs Advisory x12
-----------------------------

BNBT BitTorrent Tracker Denial Of Service
-----------------------------------------

Versions:
cbtt75_20040515
Beta 7.5 Release 2 and prior versions

Vendors:
http://bnbt.go-dedicated.com/
http://bnbteasytrack...ourceforge.net/
http://sourceforge.n...s/bnbtusermods/

Date Released - 5.21.2004

------------------------------------
Product Description from the vendor:

BNBT was written by Trevor Hogan. BNBT is a complete port of the original Python BitTorrent tracker to
C++ for speed and efficiency. BNBT also offers many additional features beyond the original Python
BitTorrent tracker, plus it's easy to use and customizable. BNBT is covered under the GNU Lesser
General Public License (LGPL).

--------
Details:

A specifically crafted HTTP GET request which contains 'Authorization: Basic A==' will cause the BNBT
server to crash. It may be possible to execute arbitrary code. Previous versions are also affected by
this vulnerability. The bug is located in util.cpp in the Util_DecodeHTTPAuth function.

--------
Exploit:

Attached to this advisory is very basic PoC code which only causes the BNBT server to crash.

--------------
Tested on:
WindowsXP SP1

peace out,

--------------------------
badpack3t
www.security-protocols.com
--------------------------


Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users



All trademarks mentioned on this page are the property of their respective owners
Copyright © 2001 - 2011 msfn.org
Privacy Policy