Re: [Full-Disclosure] Microsoft's Explorer and Internet Explorer long share name buffer overflow.

From: KF (lists) (kf_lists_at_secnetops.com)
Date: 04/30/04

  • Next message: johnny cyberpunk: "[Full-Disclosure] forgotten credit"
    To: full-disclosure@lists.netsys.com
    Date: Thu, 29 Apr 2004 18:06:12 -0400
    
    

    smbd aparantly likes them to be a 256 chars or less aparantly. =]

    Apr 27 18:26:39 CloneRiot smbd[2670]: ERROR: string overflow by 1 (256
    - 255) in safe_strcpy [AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA]

    -KF

    Lan Guy wrote:

    > http://lists.samba.org/archive/jcifs/2003-February/001782.html
    >
    > Even people like Christopher Hertel
    > http://ietf.cnri.reston.va.us/internet-drafts/draft-crhertel-smb-url-06.txt
    >
    > don't know the maximum limit of a share name.
    > I always thought that the protocol could not have more than 127
    > charaters in a single share name length.
    >
    > In any case Explorer should not crash.
    > Lan Guy
    >
    > ----- Original Message ----- From: "KF (lists)" <kf_lists@secnetops.com>
    > To: <bugtraq@securityfocus.com>
    > Cc: <full-disclosure@lists.netsys.com>
    > Sent: Thursday, April 29, 2004 2:55 AM
    > Subject: Re: [Full-Disclosure] Microsoft's Explorer and Internet
    > Explorer long share name buffer overflow.
    >
    >
    >> I would say they lied myself... I have all patches from Windows
    >> update installed including all the optional ones... still crashes for
    >> me and still tears up the EIP and EBP. My IE advertises itself as:
    >> 6.0.2800.1106 SP1; Q837009;Q8832894:Q831167 , The OS is Win2k Server
    >> 5.00.2195 SP4.
    >>
    >> Thus far I have been unable to locate a good unicode return
    >> address... but thats not to say there is not one there. =] . For
    >> those of you wondering smb.conf DOES allow for characters like \x90
    >> and other things of that nature.
    >>
    >> enjoy.
    >>
    >> -KF
    >>
    >>
    >> Paul Szabo wrote:
    >>
    >>>
    >>> Anyway, http://support.microsoft.com/?kbid=322857 lies when it says
    >>> this is
    >>> fixed in W2kSP4; or maybe that KB article refers to a different
    >>> problem: it
    >>> say the error should be "Access Violation", I got "Program Error".
    >>>
    >>> Cheers,
    >>>
    >>> Paul Szabo - psz@maths.usyd.edu.au
    >>> http://www.maths.usyd.edu.au:8000/u/psz/
    >>> School of Mathematics and Statistics University of Sydney 2006
    >>> Australia
    >>>
    >>>
    >>
    >> _______________________________________________
    >> Full-Disclosure - We believe in it.
    >> Charter: http://lists.netsys.com/full-disclosure-charter.html
    >>
    >
    > _______________________________________________
    > Full-Disclosure - We believe in it.
    > Charter: http://lists.netsys.com/full-disclosure-charter.html
    >

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: johnny cyberpunk: "[Full-Disclosure] forgotten credit"

    Relevant Pages

    • Re: DVD-RW, InCD and SBS 2003
      ... that s/w has never been officially supported on server and don't see a need ... send the data across the LAN and burn it on a PC ... > explorer will cease up. ...
      (microsoft.public.windows.server.sbs)
    • Re: Cant browse local network
      ... This box is on a separate LAN on which no comp ... Explorer has other problems. ... With a careful ear, one can hear many, many disk accesses being made ... up when the QVP Explorer integration was disabled. ...
      (microsoft.public.win2000.networking)
    • OWA Dyndns
      ... Werden die Benutzerdaten eingegeben bekomme ich eine Meldung "404 Datei ... nicht gefunden" im Explorer. ... Der Aufruf aus dem LAN heraus funktioniert. ...
      (microsoft.public.de.german.exchange2000.general)
    • Win2k Server Network Access Problem
      ... I am unable to access shared folders on certain systems on my LAN. ... When the systems are accessed using \\machinename or \\machineip, the explorer doesn't open, but i am able to ping these systems. ... Hemant A ...
      (microsoft.public.win2000.general)