Exploit code for Exchange content="" vulnerability
5 Dec. 2000
Summary
A security vulnerability was discovered a while back that allowed remote attackers to cause a denial of service attack against Exchange based mail servers. The vulnerability and its possible solution were discussed in our previous article: Exchange Server Malformed MIME Header vulnerability (Patch available).
An exploit code is now available as a proof-of-concept for this security problem.
Credit:
The information has been provided by incubus.
Exploit:
/*
*
* TESSA: The Exchange Simple Service Assimilator
* ----------------------------------------------
*
* This will crash a 'Microsoft Exchange 5.5 SP3 Internet Mail Service
* and Information Store' (what's in a name)
*
* For people who got a little brains.. translate the shellcode, it will become
* more clear for you.
*
* by incubus <incubus@securax.org> http://securax.org/incubus
*
* All my love: Tessa.
* Respect: #securax@efnet, mr_magnet, axess, f0bic, lamagra and steven.
*
*/