143
Kazaa Altnet Download Manager prior 4.0.0.4 ActiveX control buffer overflow
Peer-to-Peer
2004/09/05
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
2004/11/13
1.1
Corrected the plugin structure and added the accuracy values in 1.1
tcp
1214
open|send GET / HTTP/1.0\n\n|sleep|close|pattern_exists X-Kazaa-Username:
97
This plugin is not very accurate! You have to verify the existence of the potentially affected Altnet Download-Manager on the host.
CelebrityHacker
2004/09/03
http://secunia.com/advisories/12446
Altnet Download-Manager prior 4.0.0.4
Altnet Download-Manager newer than 4.0.0.4 or other download managers
Buffer Overflow
The target system may running the peer-to-peer software Kazaa. The popular filesharing clients Kazaa and Grokster also provide a download-manager by Altnet. This is vulnerable to a buffer overflow in the IsValidFile() method in the ADM ActiveX control. An attacker may run arbitrary web code on the target system.
Disable the peer-to-peer software if not allowed nor needed. If it should run then filter incoming traffic on port tcp/1214 to prevent unwanted access to the web service. Also de-install or de-activate or uphrade the affected Download-Manager by Altnet.
Approx. 30 minutes
No
Yes
Yes
High
7
6
9
7
12446
50657
Hacking Exposed: Network Security Secrets & Solutions, Stuart McClure, Joel Scambray and George Kurtz, February 25, 2003, 4th Edition, McGraw-Hill Osborne Media, ISBN 0072227427
http://secunia.com/product/3862/