Re: Microsoft Windows 2000 WebDAV Buffer Overflow Vulnerability

From: Renaud Deraison (deraison@nessus.org)
Date: 03/19/03

  • Next message: Royans Tharakan: "RE: Microsoft Windows 2000 WebDAV Buffer Overflow Vulnerability"
    Date: Wed, 19 Mar 2003 01:30:04 +0100
    From: Renaud Deraison <deraison@nessus.org>
    To: pen-test@securityfocus.com
    
    

    On Tue, Mar 18, 2003 at 02:38:45PM -0800, Royans Tharakan wrote:
    > Did any one try this out ?

    Yes. See the comments at the top of the plugin for the tests and their
    results.

    > Someone said that OWA is not at risk so we are not patching it for webdav.
    > I tried using this code (wrote again perl) but it doesn't work against any
    > SP3 server.

    Maybe you did not rewrite it properly - if you're not familiar with
    nasl, i'd not be surprised.

    The trick is simply to send a long argument to any web-dav related
    command. Therefore SEARCH /AAAAA[...]AAA HTTP/1.1 should work.

    Be sure to have the "too long buffer" be made of 65535 chars _exactly_.

                                    -- Renaud

    -- 
    Renaud Deraison
    The Nessus Project
    http://www.nessus.org
    ----------------------------------------------------------------------------
    Did you know that you have VNC running on your network? 
    Your hacker does. Plug your security holes now! 
    Download a free 15-day trial of VAM:
    http://www2.stillsecure.com/download/sf_vuln_list.html
    

  • Next message: Royans Tharakan: "RE: Microsoft Windows 2000 WebDAV Buffer Overflow Vulnerability"

    Relevant Pages

    • Re: CounterStrike (HalfLife?) Server possible DoS attack.
      ... The 'nextmap' chat command is an Admin-Mod command ... Furthermore, if an anti-flood plugin is installed, such ... There was a bug in Half-Life Dedicated Server (HLDS) ...
      (Vuln-Dev)
    • ANN: DS Plugin System 4.5 RC 2
      ... Dragon Soft Team is proud to announce DS Plug-in System 4.5. ... * Automatic plugin registration: ... Custom menu structures support ... TdsPluginCommand.Active - Allow enable/disable command execution. ...
      (borland.public.delphi.thirdpartytools.general)
    • Re: cmdEX.exe - augmenting the existing CMD.EXE
      ... Actually, zsh has a generic plugin to just complete based on context, no ... If you want to get fancier, one can write a plugin to enhance the command ... we stop on CHANGE and press the TAB key again. ...
      (microsoft.public.win2000.cmdprompt.admin)
    • Re: pss analysis of PLL
      ... I was trying to perform the pss analysis of my PLL but I got an error: ... Run the simulation with the VCO extraction plugin. ... Using the plugin for VCO extraction, the command line is ...
      (comp.cad.cadence)
    • Re: WinSetup on the Iyonix
      ... believe someone wrote a plugin. ... The command does work in a similar ... The Iyonix as supplied does not save WimpVisualFlags but the third party ... WimpVisualFlags information. ...
      (comp.sys.acorn.programmer)