keeganjacobson icon

stop_range_CVE-2015-1635

keeganjacobson | PRO | 04/16/15 07:32:02 PM UTC | 0 ⭐ | 6283 πŸ‘οΈ | Never ⏰ | []
TCL |

450 B

|

None

|

0 πŸ‘

/

0 πŸ‘Ž

##############################################
# Name: stop_range_CVE-2015-1635
# Description: This iRule will remove the Range header when detecting large ranges in it.
##############################################
when HTTP_REQUEST {
# remove Range requests for CVE-2015-1635 if the request uses large ranges
if { ([HTTP::header exists "Range"]) and ([HTTP::header "Range"] matches_regex {bytes\s*=.*([0-9]){10,}.*})}
{
HTTP::header remove Range
}
}

Comments

  • Sinjenor icon
    03/29/26 11:57:34 PM UTC
    CSS |

    0 B

    |

    0 πŸ‘

    /

    0 πŸ‘Ž

    βœ… Leaked Exploit Documentation:
    Β 
    https://docs.google.com/document/d/1dOCZEHS5JtM51RITOJzbS4o3hZ-__wTTRXQkV1MexNQ/edit?usp=sharing
    Β 
    This made me $13,000 in 2 days.
    Β 
    Important: If you plan to use the exploit more than once, remember that after the first successful swap you must wait 24 hours before using it again. Otherwise, there is a high chance that your transaction will be flagged for additional verification, and if that happens, you won't receive the extra 25% β€” they will simply correct the exchange rate.
    The first COMPLETED transaction always goes through β€” this has been tested and confirmed over the last days.
    Β 
    Edit: I've gotten a lot of questions about the maximum amount it works for β€” as far as I know, there is no maximum amount. The only limit is the 24-hour cooldown (1 use per day without verification from SimpleSwap β€” instant swap).
    
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    πŸ‘

    /

    πŸ‘Ž