mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-10 15:59:29 +02:00
48 lines
2.2 KiB
Markdown
48 lines
2.2 KiB
Markdown
### [CVE-2011-1473](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1473)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
** DISPUTED ** OpenSSL before 0.9.8l, and 0.9.8m through 1.x, does not properly restrict client-initiated renegotiation within the SSL and TLS protocols, which might make it easier for remote attackers to cause a denial of service (CPU consumption) by performing many renegotiations within a single connection, a different vulnerability than CVE-2011-5094. NOTE: it can also be argued that it is the responsibility of server deployments, not a security library, to prevent or limit renegotiation when it is inappropriate within a specific environment.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- http://vincent.bernat.im/en/blog/2011-ssl-dos-mitigation.html
|
|
- http://www.ietf.org/mail-archive/web/tls/current/msg07553.html
|
|
|
|
#### Github
|
|
- https://github.com/ABONASRSY/ABONSR-DOS
|
|
- https://github.com/ARPSyndicate/cvemon
|
|
- https://github.com/AeolusTF/pentmenu
|
|
- https://github.com/CVEDB/PoC-List
|
|
- https://github.com/CVEDB/awesome-cve-repo
|
|
- https://github.com/DauDau432/pentmenu
|
|
- https://github.com/GinjaChris/pentmenu
|
|
- https://github.com/Mitko1223tm/pentmenu
|
|
- https://github.com/Moulish2004/pentmenu_kali_linux_
|
|
- https://github.com/XDLDCG/bash-tls-reneg-attack
|
|
- https://github.com/alexoslabs/HTTPSScan
|
|
- https://github.com/ataskynet/ataSky-Pent
|
|
- https://github.com/blacksaw1997/erdo
|
|
- https://github.com/bootpc/pentmenu
|
|
- https://github.com/chnzzh/OpenSSL-CVE-lib
|
|
- https://github.com/crelle/pentmenu
|
|
- https://github.com/ekovegeance/DDOS
|
|
- https://github.com/gsdu8g9/ddos-42
|
|
- https://github.com/halencarjunior/HTTPSScan-PYTHON
|
|
- https://github.com/hrbrmstr/internetdb
|
|
- https://github.com/kaiiihk/pentmenu
|
|
- https://github.com/keygood/pentmenu
|
|
- https://github.com/pruehack12/pentmenu
|
|
- https://github.com/space58666/ddos
|
|
- https://github.com/thcbin/pentmenu
|
|
- https://github.com/wallaci09/cmd
|
|
- https://github.com/wiaoo/ddos
|
|
- https://github.com/yinghua8wu/P_DOS
|
|
- https://github.com/zaurhasanov/ddos
|
|
- https://github.com/zjt674449039/cve-2011-1473
|
|
|