hacking security forum

[Full-Disclosure] SecurityFocus found a vulnerability in IIS

From: BoneMachine <bonemach@sdf.lonestar.org>
Date: Wed Feb 18 2004 - 04:38:32 EST

Hello,
I was browsing through the findings of SecurityFocus and found the following:
BID 9660 - "Microsoft IIS Unspecified Remote Denial Of Service Vulnerability"

It seems that using an OpenSSL ASN.1 brute force tool IIS 5.0 can be brought to a halt.

<dramatic>
So ...
does MS use OpenSSL code?
Has anyone tested this on hosts running a more current version of IIS?
Has anyone used this tool on other "critical apps", VPNs anyone?
Is this tool the holy grail of ASN.1 testing?
Is this tool the cause that eEye has about 7 vulnerabilities waiting to be disclosed?

These are the questions running through my head, bouncing against my scull, searching for an answer.

Is there someone on this list that can help me out?
</dramatic>

greetings
Bone Machine

---
"We're going higher" - The Pixies
---
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
Received on Wed Feb 18 05:14:42 2004

This archive was generated by hypermail 2.1.8 : Wed Feb 18 2004 - 06:01:03 EST

Custom Search