IIS/WebDav Exploit List

From: Joe Stewart (jstewartat_private)
Date: Tue May 13 2003 - 06:31:38 PDT

  • Next message: Valdis.Kletnieksat_private: "Re: Folllow-up to the Hotmail/MSN password reset problems"

    I have created a page describing the various WebDav exploits and exploit
    kits I have come across so far, along with Snort signatures to detect each
    one. If anyone knows of any other unique exploits for the ntdll.dll/WebDav 
    IIS vulnerability, please send me the source/binary or a link so I can catalog 
    it here:
    
    http://www.lurhq.com/webdav.html
    
    -Joe
     
    -- 
    Joe Stewart, GCIH 
    Senior Intrusion Analyst
    LURHQ Corporation
    http://www.lurhq.com/
    
    
    ----------------------------------------------------------------------------
    *** Wireless LAN Policies for Security & Management - NEW White Paper ***
    Just like wired networks, wireless LANs require network security policies 
    that are enforced to protect WLANs from known vulnerabilities and threats. 
    Learn to design, implement and enforce WLAN security policies to lockdown enterprise WLANs.
    
    To get your FREE white paper visit us at:    
    http://www.securityfocus.com/AirDefense-incidents
    ----------------------------------------------------------------------------
    



    This archive was generated by hypermail 2b30 : Tue May 13 2003 - 11:52:22 PDT