|
|||||||||||
|
[Fwd: Re: URL Scan for IIS]
From: Mark Curphey <mark(at)curphey.com>
Date: Sun Feb 23 2003 - 23:47:36 EST
attached mail follows: It's highly effective against URL and Header overflows - of which the most recent is probably the ColdFusion/JRun overflow. It's not effective at all at many overflows that Microsoft says it is effective at preventing - the ones that occur in the body arguments. Some examples include the MSADC overflow, and the Microsoft Content Server authentication overflow. I'll be doing a more specific demo of one of those next week at BlackHat in Seattle. Stop on by. :>
Dave Aitel
On Sat, 22 Feb 2003 20:55:19 -0800
>
This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:49 EDT |
||||||||||
|
|||||||||||