Re: 2000 server exploit, webDAV

From: Roger Abell [MVP] (mvpNOSPAM@asu.edu)
Date: 03/19/03


From: "Roger Abell [MVP]" <mvpNOSPAM@asu.edu>
Date: Tue, 18 Mar 2003 21:18:58 -0700


"owen johnson" <o@bluecoat.com> wrote in message news:157801c2ed83$3e11ae40$3301280a@phx.gbl...
> I would like to adjust our network to filter for the new
> 2000 server exploit.
>
> Has Microsoft or anyone else released a request
> signature/finger-print for this issue? Specifically, an
> example of the HTTP Request headers from a packet
> capture.
>
> This would be a HUGE help.
>
>

That would pretty much be like saying,
here, this is how to do it. Besides, it would
vary based on the payload.

-- 
Roger Abell
MS MVP (Security, Windows), MCDBA,  MCSE both


Relevant Pages

  • Re: Bybass HTTP ( extension files ) in ISA 2004
    ... The request was rejected by the HTTP filter. ... Contact your ISA Server administrator. ...
    (Bugtraq)
  • Re: [Full-Disclosure] Microsoft win2003server phone home
    ... of course vice-versa, that's a privacy issue. ... but then again we're talking about microsoft. ... Is this behavior normal for a windows server installation? ... request information from an arbitrary server that I have no control over? ...
    (Full-Disclosure)
  • [REVS] NTLM HTTP Authentication is Insecure By Design
    ... in front of a web server, and that proxy server shares a single TCP ... These are attacks that make use of non-RFC HTTP requests (HTTP Request ... the authentication is associated with the ...
    (Securiteam)
  • [NT] 04WebServer Multiple Vulnerabilities (CSS, Log File Injection, AUX DoS)
    ... 04WebServer is a HTTP server developed by Soft3304 for Windows platforms. ... Characters into Log File ... filtering on the request URL before writing it into the log file. ... following HTTP request, when submitted to a vulnerable 04WebServer, will ...
    (Securiteam)
  • Re: breaking the model
    ... > The forms data then is in the Request object. ... HTTP Request; in this case, the form POST Request from the Page. ... client and server. ...
    (microsoft.public.dotnet.framework.aspnet)