RE: Microsoft Windows 2000 WebDAV Buffer Overflow Vulnerability

From: Aleksander P. Czarnowski (alekcat_private)
Date: Wed Mar 19 2003 - 06:08:13 PST

  • Next message: Rob Shein: "RE: Microsoft Windows 2000 WebDAV Buffer Overflow Vulnerability"

    > You could give a look to the related Nessus plugin : 
    >
    http://cvs.nessus.org/cgi-bin/cvsweb.cgi/~checkout~/nessus-plugins/scrip
    ts/iis_webdav_overflow.nasl
    
    First of all - just from quick testing - it seems than nessus plugin
    don't work correctly, at least one from 18th of March. Secondly you can
    use a bit brutal method of using LOCK or any other WebDAV method with
    buffer >64kb - it was already discussed on ntbugtraq and snort-sigs I
    believe. But this is still far from working exploit that gives you
    reverse shell...
    Best Regards
    Aleksander Czarnowski
    AVET INS
    
    ----------------------------------------------------------------------------
    Did you know that you have VNC running on your network? 
    Your hacker does. Plug your security holes now! 
    Download a free 15-day trial of VAM:
    http://www2.stillsecure.com/download/sf_vuln_list.html
    



    This archive was generated by hypermail 2b30 : Wed Mar 19 2003 - 09:04:41 PST