CVE-2004-1561 is a buffer overflow vulnerability in Icecast versions 2.0.1 and earlier. The flaw exists in the HTTP header parsing logic, where sending more than 31 HTTP headers in a single request causes an array overflow. This allows an attacker to overwrite the return address on the stack with a pointer to attacker-controlled shellcode, resulting in arbitrary code execution. The vulnerability primarily affects the Win32 platform but may impact other platforms under certain conditions.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (3 hidden).
This repository contains a single Metasploit module: 'Icecast Header Overwrite' (modules/exploits/windows/http/icecast_header.rb). The module exploits a buffer overflow vulnerability in Icecast versions 2.0.1 and earlier (CVE-2004-1561) on Windows. The exploit works by sending 32 specially crafted HTTP headers to the Icecast service (default port 8000), causing a one-off overwrite of a pointer array, which on Windows overwrites the saved instruction pointer (EIP), allowing arbitrary code execution. The module leverages Metasploit's payload system, supporting payloads up to 2000 bytes (excluding certain bad characters). The exploit is operational and can be used to gain code execution on vulnerable Icecast servers. The only file in the repository is the exploit module itself, written in Ruby and structured according to Metasploit conventions.
This repository contains a Python exploit script (CVE-2004-1561.py) and a brief README. The exploit targets the ICE server software vulnerable to CVE-2004-1561, a buffer overflow vulnerability. The script takes a remote host and port as arguments, crafts a malicious HTTP request containing a reverse shell payload (generated with msfvenom for Windows), and sends it to the target over TCP. If successful, the payload opens a reverse shell from the target to the attacker's machine. The exploit is operational, with a hardcoded shellcode payload, and is not part of a larger framework. The README provides minimal context, indicating this is a non-Metasploit alternative for TryHackMe exercises.
This repository contains a Python implementation of a buffer overflow exploit for Icecast (<= 2.0.1) on Windows, targeting CVE-2004-1561. The main file, 'icecast-bof.py', is a standalone exploit script that takes a target IP and port as arguments. It constructs a malicious HTTP request with a crafted buffer containing shellcode (default: Meterpreter reverse shell) and sends it to the target Icecast server over TCP. The exploit leverages a header overwrite vulnerability to achieve remote code execution. The payload is customizable and is currently set to a reverse shell generated by msfvenom. The repository is simple, with only a README and the exploit script, and is intended for use as a proof-of-concept or operational exploit against vulnerable Icecast servers.
This repository contains two exploit implementations (in C and Python) for CVE-2004-1561, a remote code execution vulnerability in Icecast Win32 versions <= 2.0.1. The C file (568-edit.c) is an edited version of a classic exploit, while icecast.py is a Python 3 rewrite inspired by the Metasploit module. Both exploits target the Icecast server over TCP (default port 8000) and deliver a user-supplied reverse shell payload. The attacker must provide their own shellcode (typically generated with msfvenom) and specify the target's IP and port. Upon successful exploitation, the target system connects back to the attacker's listener (e.g., netcat on port 443), providing a Windows command shell. The README documents usage for both exploits and references the original sources. The repository is operational and provides working exploit code, but requires the user to supply their own payload and listener setup.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.