SMBLoris Denial Of Service

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

There's a lot of talk about SMBLoris but nobody seems to have written a public efficient PoC yet, so I gave it a shot. A single instance takes down a fully patched Windows 10 Pro box with 8GiB of RAM in less than 10 seconds. I tried using Scapy initially, but it's dog slow, so I went with C. The PoC uses raw sockets to bypass the local TCP stack. It supports attacking from multiple source IPs (not requiring them to be bound to the adapter). There is rudimentary ARP support (gratuitous only, no real reply functionality). There is no throttling so some packets may be dropped. I haven't seen it completely deadlock a Windows machine yet (it keeps accepting connections and responding to pings), but it renders it completely unusable during the attack and several minutes after it ceases, and causes various kinds of persistent breakage (UI restarts, complete UI crashes, inability to start applications, I/O errors due to failure to allocate memory in the storage controller driver, etc.)...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息