RE: TTP/1.0 Remote BufferOverflow?

From: Jim Stickley (jim@garrison.com)
Date: 04/26/02


From: Jim Stickley <jim@garrison.com>
To: "'Felipe Cerqueira'" <fcerqueira@bufferoverflow.com.br>, vuln-dev@security-focus.com
Date: Fri, 26 Apr 2002 08:28:17 -0700

Generally when a server returns an error like the one listed below it means
that it didn't buffer overflow. In most cases if you overflow the buffer,
the connection will just drop.

From the looks of the error message below, the server didn't like what you
sent, but it seems to have handled it.

        -Jim

-----Original Message-----
From: Felipe Cerqueira [mailto:fcerqueira@bufferoverflow.com.br]
Sent: Thursday, April 25, 2002 8:59 PM
To: vuln-dev@security-focus.com
Subject: TTP/1.0 Remote BufferOverflow?

TTP is a httpd server for HP Print Server

Check this out:

HEAD / HTTP/1.0

HTTP/1.0 200 OK
Server:HTTP/1.0
Content-Type:text/html

.. .

GET A*lot+of+bytes HTTP/1.0
<\n\n>

 500 Internal Server Error

<HEAD><TITLE>500 Internal Server Error</TITLE></END>
<BODY><H1>500 Internal Server Error</H1></BODY>Connection closed by
foreign host

someone can verify it?
thankz

- --
sky

7218 2AFF 6166 9692 8BAA
ACA3 64E9 3941 B6E7 88E7



Relevant Pages

  • [NEWS] How to Remotely and Automatically Exploit a Format Bug
    ... Exploiting a format bug remotely is not as difficult as one would think. ... We will use very minimalist server along this paper. ... Since the buffer is directly available to a malicious user, ... Guessing the address of the shellcode in the stack ...
    (Securiteam)
  • Re: smbclient timeout, file truncated / 9.1 Pro (was Re: libpopt.so.0 conflict...
    ... >and the OS/2 machines on the LAN. ... NETBEUI was invented to allow windows clients to use an OS/2 server. ... 9 buffer small read and write requests until the buffer is full ... Acknowledgment Timeout ...
    (alt.os.linux.suse)
  • [UNIX] Multiple Vulnerabilities in Citadel/UX
    ... could allow complete control over a vulnerable server. ... Citadel server as can be seen by this simplistic code snippet: ... configuration buffers, leading to the possibility of carrying out a buffer ... int connect_to_host; ...
    (Securiteam)
  • Re: Samba HOWTO
    ... but I see no reason why eCS or Warp Server ... OS/2 LAN Requester initialization file ... 9 buffer small read and write requests until the buffer is full ... Acknowledgment Timeout ...
    (comp.os.linux.networking)
  • [Full-Disclosure] Multiple pServ Remote Buffer Overflow Vulnerabilities
    ... >There are multiple buffer overflow bugs in pServ that could lead ... >Pico Server is a freeware web server available at ...
    (Full-Disclosure)