what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

iisDoS.txt

iisDoS.txt
Posted May 29, 2003
Authored by SPI Labs | Site spidynamics.com

Microsoft IIS versions 5.0 and 5.1 are vulnerable to a denial of service attack if an attacker sends a Webdav request with a body over 49,153 bytes using the 'PROPFIND' or 'SEARCH' request methods. This results in IIS restarting itself and terminating any active sessions.

tags | exploit, denial of service
SHA-256 | 67114ae0520ebab576e477197853235affe77007a602ac27dc47708e61cc7c11

iisDoS.txt

Change Mirror Download
Internet Information Services 5.0 Denial of service

[Release Date] May 29th, 2003
Severity: High

[Systems Affected]
* Microsoft Information Server 5.0
* Microsoft Information Server 5.1

[Description]

If an attacker sends a Webdav request with a body over 49,153 bytes
using the 'PROPFIND' or 'SEARCH' request methods, IIS will be forced
to restart itself. All web server, email, and active ftp connections
will be terminated, along with a disruption of future sessions during
the time it takes IIS to restart. The complete advisory is also available
from our
website at: https://www.spidynamics.com/iis_alert.html

[Remediation]
Please install the vendor-supplied patch located at
https://www.microsoft.com/technet/security/bulletin/MS03-018.asp

[Contact Information]

SPI Labs
SPI Dynamics R&D Team
spilabs@spidynamics.com
115 Perimeter Center Place
Suite 270
Atlanta, GA 30346
Phone: (678)781-4800
Toll-Free Phone: (866)774-2700


SPI Dynamics was founded in 2000 by a team of accomplished Web security
specialists;
SPI Dynamics is the leader in Web application security technology. With such
signature
products as WebInspect, SPI Dynamics is dedicated to protecting companies'
most valuable
assets. SPI Dynamics has created a new breed of Internet security products
for the Web
application, the most vulnerable yet least secure component of online
business infrastructure.

Copyright (c) 2003 SPI Dynamics, Inc. All rights reserved worldwide.

Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    63 Files
  • 14
    Nov 14th
    18 Files
  • 15
    Nov 15th
    8 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    18 Files
  • 19
    Nov 19th
    7 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close