143 Kazaa Altnet Download Manager prior 4.0.0.4 ActiveX control buffer overflow Peer-to-Peer 2004/09/05 Marc Ruef marc dot ruef at computec dot ch http://www.computec.ch computec.ch Marc Ruef marc dot ruef at computec dot ch http://www.computec.ch computec.ch 2004/11/13 1.1 Corrected the plugin structure and added the accuracy values in 1.1 tcp 1214 open|send GET / HTTP/1.0\n\n|sleep|close|pattern_exists X-Kazaa-Username: 97 This plugin is not very accurate! You have to verify the existence of the potentially affected Altnet Download-Manager on the host. CelebrityHacker 2004/09/03 http://secunia.com/advisories/12446 Altnet Download-Manager prior 4.0.0.4 Altnet Download-Manager newer than 4.0.0.4 or other download managers Buffer Overflow The target system may running the peer-to-peer software Kazaa. The popular filesharing clients Kazaa and Grokster also provide a download-manager by Altnet. This is vulnerable to a buffer overflow in the IsValidFile() method in the ADM ActiveX control. An attacker may run arbitrary web code on the target system. Disable the peer-to-peer software if not allowed nor needed. If it should run then filter incoming traffic on port tcp/1214 to prevent unwanted access to the web service. Also de-install or de-activate or uphrade the affected Download-Manager by Altnet. Approx. 30 minutes No Yes Yes High 7 6 9 7 12446 50657 Hacking Exposed: Network Security Secrets & Solutions, Stuart McClure, Joel Scambray and George Kurtz, February 25, 2003, 4th Edition, McGraw-Hill Osborne Media, ISBN 0072227427 http://secunia.com/product/3862/