FW: Footprints of ASP ISAPI filter buffer overflows

From: Jonathon.Kalaugher@sbg-ap.com
Date: 04/12/02


From: Jonathon.Kalaugher@sbg-ap.com
To: incidents@securityfocus.com
Date: Fri, 12 Apr 2002 15:34:22 +1200


> Hello security people,
>
> re: Cumulative Patch for Internet Information Services (Q319733)
>
> Has anybody found or know of a "footprint" left by the ASP ISAPI extension
> overflow in IIS web logs?
>
> Has anybody a copy of some log files that contain such for general review
> by the community?
>
> A customer was vulnerable to this attack and I would like to find out if
> he was compromised.
>
> Thanking you all in advance.
>
> Jon
>

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com



Relevant Pages

  • [NT] Buffer Overflow in Microsoft Rasapi32.dll
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... The overflow occurs when the code that parses RAS phonebook entries runs; ... - Create a batch file adding your account to the "administrators" group ...
    (Securiteam)
  • flac123 0.0.9 - Stack overflow in comment parsing
    ... flac123 0.0.9 - Stack overflow in comment parsing ... Verified code execution on FreeBSD 6.2 - should affect most ... This allows for the execution of arbitrary code. ... iSEC Partners is a full-service security consulting firm that provides ...
    (Bugtraq)
  • [VulnWatch] Internet Explorer Plugin.ocx heap overflow (#NISR24042003)
    ... NGSSoftware Insight Security Research Advisory ... Internet Explorer ActiveX Control Heap Overflow ... NGSSoftware alerted Microsoft to this vulnerability on 13th December 2002. ...
    (VulnWatch)
  • [NT] Multiple Buffer Overruns RealOne / RealPlayer / RealOne Enterprise
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Beyond Security would like to welcome Tiscali World Online ... RealOne is the updated version of RealPlayer. ... within the SMIL file a heap overflow would occur in RealPlay.exe. ...
    (Securiteam)
  • ITS4 from Cigital flawed
    ... "When it comes to software security, there's no such thing as a small ... And then it offers this neat little code scanning tool called ITS4. ... have kept each and every example overflow from being exploitable. ...
    (Bugtraq)