Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2016-6515

Description

The auth_password function in auth-passwd.c in sshd in OpenSSH before 7.3 does not limit password lengths for password authentication, which allows remote attackers to cause a denial of service (crypt CPU consumption) via a long string.

POC

Reference

- http://packetstormsecurity.com/files/140070/OpenSSH-7.2-Denial-Of-Service.html

- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html

- https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf

- https://www.exploit-db.com/exploits/40888/

Github

- https://github.com/ARPSyndicate/cve-scores

- https://github.com/ARPSyndicate/cvemon

- https://github.com/CVEDB/PoC-List

- https://github.com/CVEDB/awesome-cve-repo

- https://github.com/CVEDB/top

- https://github.com/GhostTroops/TOP

- https://github.com/HACK-MR-B/OpenSSH-7.2-Denial-of-Service-Vulnerability

- https://github.com/JERRY123S/all-poc

- https://github.com/Live-Hack-CVE/CVE-2016-6515

- https://github.com/Maribel0370/Nebula-io

- https://github.com/NCSU-DANCE-Research-Group/CDL

- https://github.com/NeoOniX/5ATTACK

- https://github.com/anquanscan/sec-tools

- https://github.com/bioly230/THM_Skynet

- https://github.com/cocomelonc/vulnexipy

- https://github.com/cved-sources/cve-2016-6515

- https://github.com/cyberanand1337x/bug-bounty-2022

- https://github.com/hktalent/TOP

- https://github.com/jbmihoub/all-poc

- https://github.com/jptr218/openssh_dos

- https://github.com/lekctut/sdb-hw-13-01

- https://github.com/n0-traces/cve_monitor

- https://github.com/opsxcq/exploit-CVE-2016-6515

- https://github.com/pedr0alencar/vlab-metasploitable2

- https://github.com/phx/cvescan

- https://github.com/retr0-13/cveScannerV2

- https://github.com/scmanjarrez/CVEScannerV2

- https://github.com/scmanjarrez/test

- https://github.com/vshaliii/Basic-Pentesting-2-Vulnhub-Walkthrough

- https://github.com/weeka10/-hktalent-TOP