cve/2010/CVE-2010-5107.md

38 lines
1.7 KiB
Markdown
Raw Normal View History

2024-05-26 14:27:05 +02:00
### [CVE-2010-5107](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-5107)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen)
### Description
The default configuration of OpenSSH through 6.1 enforces a fixed time limit between establishing a TCP connection and completing a login, which makes it easier for remote attackers to cause a denial of service (connection-slot exhaustion) by periodically making many new TCP connections.
### POC
#### Reference
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
#### Github
- https://github.com/ARPSyndicate/cvemon
- https://github.com/DButter/whitehat_public
- https://github.com/Dokukin1/Metasploitable
- https://github.com/George210890/13-01.md
- https://github.com/Iknowmyname/Nmap-Scans-M2
- https://github.com/McStork/check_maxtcp
- https://github.com/NikulinMS/13-01-hw
- https://github.com/SergeiShulga/13_1
- https://github.com/StepanovSA/InfSecurity1
- https://github.com/VictorSum/13.1
- https://github.com/Wernigerode23/Uiazvimosty
- https://github.com/Zhivarev/13-01-hw
- https://github.com/kaio6fellipe/ssh-enum
- https://github.com/phx/cvescan
- https://github.com/smabramov/Vulnerabilities-and-attacks-on-information-systems
- https://github.com/syadg123/pigat
- https://github.com/teamssix/pigat
- https://github.com/vioas/Vulnerabilities-and-attacks-on-information-systems
- https://github.com/vshaliii/DC-1-Vulnhub-Walkthrough
- https://github.com/zzzWTF/db-13-01