Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2011-1473

Description

OpenSSL before 0.9.8l, and 0.9.8m through 1.x, does not properly restrict client-initiated renegotiation within the SSL and TLS protocols, which might make it easier for remote attackers to cause a denial of service (CPU consumption) by performing many renegotiations within a single connection, a different vulnerability than CVE-2011-5094. NOTE: it can also be argued that it is the responsibility of server deployments, not a security library, to prevent or limit renegotiation when it is inappropriate within a specific environment

POC

Reference

- http://vincent.bernat.im/en/blog/2011-ssl-dos-mitigation.html

- http://www.ietf.org/mail-archive/web/tls/current/msg07553.html

Github

- https://github.com/ABONASRSY/ABONSR-DOS

- https://github.com/ARPSyndicate/cve-scores

- https://github.com/ARPSyndicate/cvemon

- https://github.com/AeolusTF/pentmenu

- https://github.com/CVEDB/PoC-List

- https://github.com/CVEDB/awesome-cve-repo

- https://github.com/DauDau432/pentmenu

- https://github.com/GinjaChris/pentmenu

- https://github.com/Mitko1223tm/pentmenu

- https://github.com/Moulish2004/pentmenu_kali_linux_

- https://github.com/Nissiuser/Vulnerability-Scan-Report

- https://github.com/XDLDCG/bash-tls-reneg-attack

- https://github.com/aaronamran/Vulnerability-Scanning-Lab-with-OpenVAS-and-Metasploitable2

- https://github.com/alexoslabs/HTTPSScan

- https://github.com/ataskynet/ataSky-Pent

- https://github.com/blacksaw1997/erdo

- https://github.com/bootpc/pentmenu

- https://github.com/chnzzh/OpenSSL-CVE-lib

- https://github.com/crelle/pentmenu

- https://github.com/ekovegeance/DDOS

- https://github.com/gsdu8g9/ddos-42

- https://github.com/halencarjunior/HTTPSScan-PYTHON

- https://github.com/hrbrmstr/internetdb

- https://github.com/kaiiihk/pentmenu

- https://github.com/keygood/pentmenu

- https://github.com/pruehack12/pentmenu

- https://github.com/shashank181034/Task3ElevateLabs

- https://github.com/space58666/ddos

- https://github.com/thcbin/pentmenu

- https://github.com/wallaci09/cmd

- https://github.com/wiaoo/ddos

- https://github.com/yinghua8wu/P_DOS

- https://github.com/zaurhasanov/ddos

- https://github.com/zjt674449039/cve-2011-1473