Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: IIS Vulnerability Content-Type overflow

From: Dan Hanson <dhanson(at)securityfocus.com>
Date: Tue Dec 03 2002 - 18:10:25 EST


Hi, We were interested in testing this out and were unable to reproduce the results that you say you saw. Taking your exploit, the only way we could get any reaction is by sending multiple small size packets in a loop. In this case, it is more of a traditional packet based DoS

You are right about it not logging the connection though.

I tried both a sp2 patched and a fully patched Windows 2000 Server machine. What are the specific values you pass the perl program to cause the DoS situation? Does the service crash? does the memory usage spike?

I also tried ensuring that the requested resource was available, and changed protocol specs.

Thanks

D

On Mon, 2 Dec 2002, at4r wrote:

> ------------------------ 3wdesign.es security ------------------------
> Advisory: IIS Vulnerability Content-Type overflow
> discovered: November 26, 2002
Received on Tue Dec 3 18:30:58 2002

Do you need help?X

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:37 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library