[VulnDiscuss] Re: iis 0day exploit
Florian Weimer <[email protected]>
| Newsgroups | gmane.comp.security.vulnerabilities.watch.general |
|---|---|
| Message-ID | <[email protected]> |
Rafael Nuñez <[email protected]> writes: > exploit at http://rafa.h0stile.net/iis_txt.c char* s1="POST "; /* HTTP/1.1\r\n"; */ char* s2="Accept: */*\r\n"; char* s4="Content-Type: application/x-www-form-urlencoded\r\n"; char* s5="Transfer-Encoding: chunked\r\n\r\n"; Looks like CAN-2002-0079, but I haven't check this. If this is an exploit for CAN-2003-0109, we are screwed because the URLScan and "disable WebDAV" workarounds are unlikely to help. -- Florian Weimer [email protected] University of Stuttgart http://CERT.Uni-Stuttgart.DE/people/fw/ RUS-CERT fax +49-711-685-5898