Re: [Full-Disclosure] Exploit Identification Request

From: Cedric Blancher (blancher_at_cartel-securite.fr)
Date: 04/29/04

  • Next message: Thorolf: "Re: [Full-Disclosure] Exploit Identification Request"
    To: root@transientimages.com
    Date: Thu, 29 Apr 2004 16:26:08 +0200
    
    

    Le jeu 29/04/2004 à 15:34, System Administrator a écrit :
    > One of our external systems (W2k, fully patched all components -
    > sp4, sql sp4, mdac sp3, post hotfixes, etc) is being hit by what
    > appears to be a buffer overflow of IIS : 4096 bytes cycling in
    > what appears to be an attempt to execute code. The probe starts by
    > obtaining an index.asp page, and then drops a "SEARCH / 411 210
    > 42" before dropping the "AAAAA<n>" string.
    [...]
    > SEARCH /AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[...]

    Looks like Windows ntdll.dll buffer overflow exploit :

            http://www.securityfocus.com/bid/7116/

    -- 
    http://www.netexit.com/~sid/
    PGP KeyID: 157E98EE FingerPrint: FA62226DA9E72FA8AECAA240008B480E157E98EE
    >> Hi! I'm your friendly neighbourhood signature virus.
    >> Copy me to your signature file and help me spread!
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html
    

  • Next message: Thorolf: "Re: [Full-Disclosure] Exploit Identification Request"

    Relevant Pages

    • Re: OpenVPN?
      ... Le jeu 17/06/2004 à 18:10, Martin Menhart, B.Sc. m-sys ... EDV-Dienstleistungen a écrit: ... > A lot of things can be done via ssh-tunnels, but not everything, ... I'm your friendly neighbourhood signature virus. ...
      (Focus-Linux)
    • Re: [Full-Disclosure] Another false Citibank e-mail...a new phishing?
      ... Christian a écrit: ... > phish credit card numbers?? ... it seems quite reasonnable for a phisher to use a ... I'm your friendly neighbourhood signature virus. ...
      (Full-Disclosure)
    • Re: [Full-Disclosure] Paper Release
      ... IHC team a écrit: ... list charter. ... I'm your friendly neighbourhood signature virus. ...
      (Full-Disclosure)
    • Re: Static ARP table in Linux
      ... Christoph Scheurer a écrit: ... PGP KeyID: 157E98EE FingerPrint: FA62226DA9E72FA8AECAA240008B480E157E98EE ... I'm your friendly neighbourhood signature virus. ...
      (Focus-Linux)