Personal Web Sharing remote stop

From: Jass Seljamaa (jassat_private)
Date: Wed May 09 2001 - 22:32:43 PDT

  • Next message: Albrecht Guenther: "security hole in os groupware suite PHProjekt"

    Personal Web Sharing Remote Stop.
    
    Versions affected: Personal Web sharing v1.5.5, probably earlier.
    
    Problem:	
    Personal Web Sharing extension, which ships with MacOS 9, can\'t handle 
    a request longer than 6000 characters. A request, which contains 6000 or 
    more characters seems to stop the file sharing, probably to avoid a 
    system freeze. Web sharing can easily be started up again in seconds. 
    
    Exploit:
    http://fileserver/?aaaaaaaaa... [approx. 6000 characters]
    
    Solution: Nothing. Vendor not contacted, I\'m sure he\'s aware of that.
    
    
    
    
    Jass Seljamaa,
    jassat_private
    
    
    -------------------------------------------------
    This mail sent through IMP: email.isp.ee
    



    This archive was generated by hypermail 2b30 : Tue May 15 2001 - 03:08:32 PDT