IIS Chunked Encoding Transfer Buffer Overflow Vulnerability

From: Rob Pope (rob.pope@vigilante-uk.com)
Date: 07/09/02


Date: 9 Jul 2002 14:13:10 -0000
From: Rob Pope <rob.pope@vigilante-uk.com>
To: pen-test@securityfocus.com


('binary' encoding is not supported, stored as-is)

Hi,

I am testing an IIS5 server at the moment and my automated vulnerability
tool reports that the server is vulnerable to the IIS Chunked Encoding
Transfer Buffer Overflow Vulnerability.

I am trying to confirm this remotely by using the proof of concept script
at http://online.securityfocus.com/bid/4485/exploit/ on iisstart.asp. I'm
getting back a HTTP/1.1 100 Continue response.

Can anyone confirm whether this is a positive response?

Many Thanks

----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/



Relevant Pages

  • SecurityFocus Microsoft Newsletter #196
    ... SecurityFocus ... MPlayer GUI File Name Buffer Overflow Vulnerability ... Relevant URL: http://www.securityfocus.com/bid/10612 ... Netegrity IdentityMinder is a tool designed for the Microsoft Windows platform to manage and maintain users and user accounts. ...
    (Focus-Microsoft)
  • SecurityFocus Microsoft Newsletter #191
    ... SecurityFocus ... MiniShare Server Remote Denial Of Service Vulnerability ... Relevant URL: http://www.securityfocus.com/bid/10409 ... Platforms: Windows 95/98, Windows NT ...
    (Focus-Microsoft)
  • RE: Vulnebrability level definition
    ... > vulnerability to it will have maximum impact," even though ... >> This list is provided by the SecurityFocus Security ... >> Intelligence Alert Service. ... >> SecurityFocus' SIA service which automatically alerts you to ...
    (Pen-Test)
  • Re: XSS Questions
    ... The vulnerability is in that the server does not sanitize data it sends to ... Being new to XSS and seing alot of messages in the ... This list is provided by the SecurityFocus Security Intelligence Alert ...
    (Pen-Test)
  • XP Personal Firewall
    ... I've come across a few XP hosts that are trying to be sneaky with the ... Apache Chunked Encoding Vulnerability on AIX ... > This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)