iParty server shuts down by sending characters to port

Risk Level: Low risk vulnerability  Low

Check or Attack Name: iParty denial of service

Platforms: iParty
Description:

A denial of service attack exists against iParty servers. If a remote user connects to the iParty port (port 6004 is default) and sends a large amount of ^? Characters, the iParty server will shut itself down and disconnect all users. No event of this shows up in the iParty log.

Remedy:

There is no workaround for this vulnerability until a patch is available from iParty.

References:

BUGTRAQ Mailing List, iParty can be shut down remotely, http://www.netspace.org/cgi-bin/wa?A2=ind9812a&L=bugtraq&F=&S=&P=68


X-Force Logo
Know Your Risks