RE: Microsoft Windows 2000 WebDAV Buffer Overflow Vulnerability

From: Frank Knobbe (fknobbe@knobbeits.com)
Date: 03/19/03

  • Next message: Ben Klang: "Re: modem protective device?"
    From: Frank Knobbe <fknobbe@knobbeits.com>
    To: Royans Tharakan <RTharakan@ingenuity.com>
    Date: 19 Mar 2003 12:25:15 -0600
    

    On Tue, 2003-03-18 at 22:02, Royans Tharakan wrote:
    > I checked this out. SANS had an emergency webcast this morning
    > in which a lot of security engineers reviewed this bug. Few microsoft
    > guys where there who confirmed that OWA uses its own version of WEBDAV
    > which overrides the version which is installed by the OS.
    > They said the version of WEBDAV in OWA is not vulnerable to this exploit.

    However, those same folks said that it is not the LOCK method that is
    vulnerable, but in fact only the GET method. I heard reports from guys
    who just couldn't make WebDAV crash with GET, but didn't have a problem
    with SEARCH and PROPFIND. Personally, I'm wondering if ISS was just
    spreading misinformation to confuse the potential worm-writers, but I'm
    not making any such accusation. (Misinformation wouldn't be effective
    anyway. But then again, neither is holding back the details for a sig,
    but explaining how it works...:/

    I think it's safe to assume that any WebDAV method, and perhaps others,
    not yet discovered components, are vulnerable, mainly because the bug is
    in ntdll.dll. So perhaps OWA is vulnerable.... we just haven't found out
    where and how....

    Regards,
    Frank

    
    



  • Next message: Ben Klang: "Re: modem protective device?"

    Relevant Pages

    • Re: Cant Connect Outlook OWA Tiger Entourage 2004
      ... > I'm having the exact same issue. ... >> I've tried to connect directly to OWA using webdav from finder (i.e. ... >> (because I get a dialog requesting my userid and pwd, which I supply, ...
      (microsoft.public.mac.office.entourage)
    • Re: OWA 2007 Forms, Toolbars, and Send Message Customizations
      ... getting that WebDAV friendly URL. ... they have just introduced some OWA customization features with SP1. ... In 2007 it looks like the scripts ... Javascript was used to send in some querystring data into our ...
      (microsoft.public.exchange.development)
    • Re: Anyone tried WebDAV development with E12 yet?
      ... WebDAV were closely coupled, with the difference of invoking OWA vs. WebDAV ... on GET and POST was the absence of Translate: ... goes away and is replaced by the new E12 OWA. ...
      (microsoft.public.exchange.development)
    • Re: Start/due dates not showing up in OWA when creating thru Webdav
      ... If you need WebDAV API for Exchange server, ... fine with the due date listed as "None" in OWA. ...
      (microsoft.public.exchange2000.development)
    • Re: Cant Connect Outlook OWA Tiger Entourage 2004
      ... I'm having the exact same issue. ... I'm using Tiger, Entourage 2004. ... > because I can access OWA from Safari no problem. ... > I've tried to connect directly to OWA using webdav from finder (i.e. ...
      (microsoft.public.mac.office.entourage)

  • Quantcast