RE: [VulnDiscuss] Re: iis 0day exploit
"Joshua Wright" <[email protected]>
| Newsgroups | gmane.comp.security.vulnerabilities.watch.general |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 This is a re-post of code to exploit CAN-2002-0079, MS02-018 (http://icat.nist.gov/icat.cfm?cvename=can-2002-0079. This post from on BUGTRAQ from 5/4/2002 looks familiar. :) http://www.securityfocus.com/archive/1/270965/2002-05-01/2002-05-07/0 - -Joshua Wright Senior Network and Security Architect Johnson & Wales University [email protected] http://home.jwu.edu/jwright/ pgpkey: http://home.jwu.edu/jwright/pgpkey.htm fingerprint: FDA5 12FC F391 3740 E0AE BDB6 8FE2 FC0A D44B 4A73 > -----Original Message----- > From: Florian Weimer [mailto:[email protected]] > Sent: Friday, March 21, 2003 2:52 PM > To: [email protected] > Subject: [VulnDiscuss] Re: [VulnWatch] iis 0day exploit > > > Rafael Nuñez <[email protected]> writes: > > > exploit at http://rafa.h0stile.net/iis_txt.c > > char* s1="POST "; /* HTTP/1.1\r\n"; */ > char* s2="Accept: */*\r\n"; > char* s4="Content-Type: application/x-www-form-urlencoded\r\n"; > char* s5="Transfer-Encoding: chunked\r\n\r\n"; > > Looks like CAN-2002-0079, but I haven't check this. If this is an > exploit for CAN-2003-0109, we are screwed because the URLScan and > "disable WebDAV" workarounds are unlikely to help. > > -- > Florian Weimer [email protected] > University of Stuttgart > http://CERT.Uni-Stuttgart.DE/people/fw/ > RUS-CERT fax +49-711-685-5898 > -----BEGIN PGP SIGNATURE----- Version: PGPfreeware 6.5.8 for non-commercial use <http://www.pgp.com> Comment: Signed by Joshua Wright <[email protected]> iQA/AwUBPny39Y/i/ArUS0pzEQLMwgCg6VBUhI9re8iJOVgCUCuz4aiAnioAn2Gb zXeANnMxWmbEBUPkMAFnWAMZ =QI21 -----END PGP SIGNATURE-----