Re: Microsoft Security Bulletin - MS03-007

From: ARAI Yuu (y.arai@LAC.CO.JP)
Date: 03/18/03

  • Next message: Russ: "Alert: Problems with MS03-007 installed"
    Date:         Tue, 18 Mar 2003 20:23:06 +0900
    From: ARAI Yuu <y.arai@LAC.CO.JP>
    To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    
    

    Hello,

    I confirmed the buffer overflow would occur when I sent a WebDAV request
    like following:

      LOCK /[buffer] HTTP/1.1
      Host: SNS

    Where [buffer] is approx 65500 bytes.

    Tested System:
    --------------
    Windows 2000 Server Japanese Edition + Windows 2000 Service Pack 3

    Thanks,
    -----------------------------------------------
    ARAI Yuu <y.arai@lac.co.jp>
    Chief Researcher / LAC Computer Security Laboratory
    http://www.lac.co.jp/security/english/

    oooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo
    Delivery co-sponsored by TruSecure
    oooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo
    FREE WEBINAR: ICSA LABS' 2002 VIRUS PREVALENCE SURVEY RESULTS!

    Join TruSecure and the ICSA Labs next Tuesday, March 18th, for our FREE
    webinar previewing the results of the ICSA Labs' 8th Annual Virus Prevalence
    Survey. Hear from the experts on the latest Internet attack trends,
    corporate security measures and virus/malware expectations for 2003, with
    recommendations on what you can do now to protect your organization. This
    webinar sells out every year, so click below to sign up today!

    www.trusecure.com/offer/s0080/

    oooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo


  • Next message: Russ: "Alert: Problems with MS03-007 installed"