OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
[Full-disclosure] Cisco CSS WebNS ssh crash

From: NetExpress (NetExpresstiscali.it)
Date: Thu Aug 30 2007 - 11:02:36 CDT


Undocument bug on Cisco CSS series 11000 with Webns 8.20.0.1

Cisco CSS series 11000 with webns system and ssh daemon crash on ssh
crc32 old 2001 exploit

Cisco CSS :
Webns Version: 08.20.0.01 (using command sh ver)
SSH Version: SSHield version 1.6.1, SSH version OpenSSH_3.0.2p1 (using
command sh sshd version)

CSS is default configured with max 5 concurrency session

with old shack exploit css does not relase connection and when it get 5
connection it crashes with no other possibility of connection

Alessandro Fiorenzi aka NetExpress

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/