ObserverIP Scan Tool 1.4.0.1 - 拒绝服务 (PoC) 漏洞概述 漏洞标题: ObserverIP Scan Tool 1.4.0.1 - Denial of Service (PoC) EDB-ID: 45204 作者: Gionathan "John" Reale 发布日期: 2018-08-16 漏洞类型: 拒绝服务 (DoS) 受影响平台: Windows x86 6-64 影响范围 受影响软件: ObserverIP Scan Tool 受影响版本: 1.4.0.1 测试环境: Windows 10 修复方案 页面未提供具体的补丁或修复方案,仅提供了利用代码(PoC)。 利用代码 (PoC) ```python #!/usr/bin/python Exploit Title: ObserverIP Scan Tool 1.4.0.1 - Denial of Service (PoC) Author: Gionathan "John" Reale Discovery Date: 2018-08-16 Homepage: https://www.ambientweather.com Software Link: https://pt0.secure.hostingprod.com/site/ambientweatherstore.com/ssl/lptools/IPTools64bit.exe Tested Version: 1.4.0.1 Tested on OS: Windows 10 Steps to Reproduce: Run the python exploit script, it will create a new file with the name "exploit.txt" just copy the text inside "exploit.txt" and start the program. Now click "Okay" and in the new window paste the content of "exploit.txt" into the following fields: "IP". Click "Search" and you will see a crash.