[VulnWatch] Re: Switch Off Multiple Vulnerabilities

From: Peter Winter-Smith (peter4020_at_hotmail.com)
Date: 01/02/04

  • Next message: advisory_at_security-corporation.com: "[VulnWatch] [SCSA-025] Invision Power Board SQL Injection Vulnerability"
    To: bugs@securitytracker.com, bugtraq@securityfocus.com, news@securiteam.com, vuln@secunia.com, vuln@security.nnov.ru, vulndb@securityfocus.com, vulnwatch@vulnwatch.org
    Date: Fri, 02 Jan 2004 02:07:36 +0000
    
    

    Hi,

    Re: http://www.elitehaven.net/switchoff.txt

    I neglected to mention the fact that just issuing a regular HTTP GET
    request with no other headers seems to cause the application to error
    within the module 'msvcrt.dll'. I have not attempted to investigate why
    this happens. Such a request may be as follows:

    --------------------------------------------------------------
    GET / HTTP/1.1

    --------------------------------------------------------------

    How strange ;o)

    -Peter Winter-Smith

    _________________________________________________________________
    Find a cheaper internet access deal - choose one to suit you.
    http://www.msn.co.uk/internetaccess


  • Next message: advisory_at_security-corporation.com: "[VulnWatch] [SCSA-025] Invision Power Board SQL Injection Vulnerability"

    Relevant Pages

    • Re: Switch Off Multiple Vulnerabilities
      ... I neglected to mention the fact that just issuing a regular HTTP GET ... request with no other headers seems to cause the application to error ... Such a request may be as follows: ...
      (Bugtraq)
    • Re: HTTP - basic authentication example.
      ... or *never* knowing the realm..) ... This is called authentication and is implemented ... requests a web page it sends a request to the server. ... consists of headers with certain information about the request. ...
      (comp.lang.python)
    • Re: Is there a way to obtain a Session object other than the current one ?
      ... > have headers, requests and responses do. ... When I said "same headers of the current page" I should have said "the ... When a request for MyImage.gif is sent to the server, ... I (the client control) want to be like the tag. ...
      (microsoft.public.dotnet.framework.aspnet)
    • Re: HttpWebRequest and Host header (ANSWERED)
      ... However there is a subtle difference in the request ... headers sent with this method, and what the actual request should be ... Host: www.company.com ...
      (microsoft.public.dotnet.framework)
    • Re: Writing a file in Response
      ... IE has a history of issues with the cache related control headers. ... to the request for one reason - to force IE to make the request. ... I think at the moment it is recognising the file via extension, and not by MIME type, I can also back this up by removing MIME information from the registry and it still works. ... In the morning I am going to simply compare a working set of headers to the headers that do not work, and that should provide the answer. ...
      (microsoft.public.dotnet.languages.vb)