2000 server exploit, webDAV

From: owen johnson (o@bluecoat.com)
Date: 03/18/03


From: "owen johnson" <o@bluecoat.com>
Date: Tue, 18 Mar 2003 11:19:05 -0800


I would like to adjust our network to filter for the new
2000 server exploit.

Has Microsoft or anyone else released a request
signature/finger-print for this issue? Specifically, an
example of the HTTP Request headers from a packet
capture.

This would be a HUGE help.

Here's a snippet from the trusecure site:

Summary:
Credible sources indicate that an exploit exists to
compromise IIS
5.0 servers on Windows 2000 including all service packs.
This
exploits an unchecked buffer in the World Wide Web
Distributed
Authoring and Versioning (WebDAV) protocol

http://www.microsoft.com/technet/treeview/default.asp?
url=/technet/security/
bulletin/MS03-007.asp



Relevant Pages

  • Re: [Full-Disclosure] Microsoft win2003server phone home
    ... of course vice-versa, that's a privacy issue. ... but then again we're talking about microsoft. ... Is this behavior normal for a windows server installation? ... request information from an arbitrary server that I have no control over? ...
    (Full-Disclosure)
  • [REVS] NTLM HTTP Authentication is Insecure By Design
    ... in front of a web server, and that proxy server shares a single TCP ... These are attacks that make use of non-RFC HTTP requests (HTTP Request ... the authentication is associated with the ...
    (Securiteam)
  • [NT] 04WebServer Multiple Vulnerabilities (CSS, Log File Injection, AUX DoS)
    ... 04WebServer is a HTTP server developed by Soft3304 for Windows platforms. ... Characters into Log File ... filtering on the request URL before writing it into the log file. ... following HTTP request, when submitted to a vulnerable 04WebServer, will ...
    (Securiteam)
  • Re: breaking the model
    ... > The forms data then is in the Request object. ... HTTP Request; in this case, the form POST Request from the Page. ... client and server. ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: Anonymous Anonymity - Request For Comments
    ... > and request that you reply directly to my e-mail address. ... > for the entity wishing to preserve their anonymity. ... > the machine can perform as a Intermediary Server and / or as a Intermediary ... > The software then attempts connection to a Intermediary Server. ...
    (Bugtraq)