|
@ollypwn | |||||
|
PoC (Denial-of-Service) for CVE-2020-0609 & CVE-2020-0610
Please use for research and educational purpose only.
github.com/ollypwn/BlueGa… pic.twitter.com/R43AHUwGV0
|
||||||
|
||||||
|
1aN0rmus
@TekDefense
|
24. sij |
|
For detection purposes, you have PCAP you can share of the tool in action?
|
||
|
|
||
|
ollypwn
@ollypwn
|
24. sij |
|
RD Gateway uses DTLS, which is TLS for UDP, so all traffic is encrypted. So there is really no way to tell if a single packet is malicious. But I can record a PCAP for you. DM me
|
||
|
|
||
|
Benjamin Pill
@BenjaminPill
|
28. sij |
|
the script seems to get stuck if a host is checked which doesn't use UDP am i right?
|
||
|
|
||
|
ollypwn
@ollypwn
|
28. sij |
|
There are some errors because of threading in openssl, so the connection are under some circumstances not terminated by signals. I haven't looked for at solution to this. But yes, you might be right about that
|
||
|
|
||
|
LAWRENCE MBURU
@lawz_secure
|
26. sij |
|
Connection not responding on dos mode
Check mode says the host is vulnerable
|
||
|
|
||
|
⛧ ʲªͷ ҎΩΰⱠᶊἕא
@Jan0fficial
|
24. sij |
|
"Please use for research and educational purpose only"
yeah.... this will not help you.. pic.twitter.com/qZXq2U89E1
|
||
|
|
||
|
Carl Schou / vm
@vm_call
|
24. sij |
|
hvad laver du oppe efter din sengetid, gå i seng
|
||
|
|
||
|
Chai Yi Chen
@Hacker_Chai
|
24. sij |
|
I think a python port might be a bit hard, keeps giving me SEC_E_ILLEGAL_MESSAGE here. I suspect it might be the TLS heartbeat extension.
|
||
|
|
||