Re: New Secuity Vulnerabilities

From: Antonio Stano (adminat_private)
Date: Fri Jun 06 2003 - 10:59:03 PDT

  • Next message: dong-h0un U: "[Full-Disclosure] Small buffer format string attack"

    
     ('binary' encoding is not supported, stored as-is)
    In-Reply-To: <20030605221703.78677.qmailat_private>
    
    Also here,
    several installs of 2003 server edition, english version with iis6 and 
    asp.net installed and running
    but this doesn't work!
    
    Antonio Stano
    Security Admin
    http://www.securityinfos.com
    
    > 
    >> Had a friend with a few 2K3 servers try this.
    >> Apparently it wasn't 
    >> present on two virgin installs w/o ISS, nor on a
    >> testing machine with IIS 
    >> (and probably the world) installed.
    >
    >I, too, have tried this against several virgin
    >installs, to no avail.  
    >
    >Could the OP, or someone who does find this, run
    >'netstat -ano' or fport on the system to see what app
    >is listening?
    >
    >Tahnks,
    >
    >Harlan
    >
    >
    >
    >__________________________________
    >Do you Yahoo!?
    >Yahoo! Calendar - Free online calendar with sync to Outlook(TM).
    >http://calendar.yahoo.com
    >
    



    This archive was generated by hypermail 2b30 : Fri Jun 06 2003 - 16:05:19 PDT