|
|||||||||||
|
RE: [Snort-sigs] WebDAV nessus script?
From: Tobia,Paul <PTOBIA(at)cerner.com>
Date: Tue Mar 18 2003 - 18:16:20 EST There's a post on NTBugTraq from ARAI Yuu <y.arai@lac.co.jp> that claims LOCK did work. He used a buffer >65000. Joe can you confirm... anyone else? alert tcp any any -> any any (msg:"Possible WebDAV Overrun PROPFIND"; content:"PROPFIND /"; flow: to_server,established; dsize: >20000;)
-----Original Message-----
On Tuesday 18 March 2003 02:32 pm, Paul Tobia wrote: > In unsafe mode it dumps "SEARCH /{65535 random overrun chars}
I tested the overflow using a custom script based on the Nessus plugin. I
tested overflowing all of the following methods: OPTIONS, TRACE, GET, HEAD,
DELETE, PUT, POST, COPY, MOVE,
HTTP/1.1 500 Internal Server Failure
<body><h1>HTTP/1.1 500 Internal Server Error(exception)</h1></body> IIS did not actually stop running, and there were no exceptions logged in the Win2K event viewer -Joe -- Joe Stewart, GCIH Senior Intrusion Analyst LURHQ Corporation http://www.lurhq.com/ CONFIDENTIALITY NOTICE This message and any included attachments are from Cerner Corporation and are intended only for the addressee. The information contained in this message is confidential and may constitute inside or non-public information under international, federal, or state securities laws. Unauthorized forwarding, printing, copying, distribution, or use of such information is strictly prohibited and may be unlawful. If you are not the addressee, please promptly delete this message and notify the sender of the delivery error by e-mail or you may call Cerner's corporate offices in Kansas City, Missouri, U.S.A at (+1) (816)221-1024. ---------------------------------------- -- ------------------------------------------------------- This SF.net email is sponsored by: Does your code think in ink? You could win a Tablet PC. Get a free Tablet PC hat just for playing. What are you waiting for? http://ads.sourceforge.net/cgi-bin/redirect.pl?micr5043en _______________________________________________ Snort-sigs mailing list Snort-sigs@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/snort-sigsReceived on Tue Mar 18 18:45:59 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:08:26 EDT |
||||||||||
|
|||||||||||