OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Bugtraq Archives: Crash FrontPage Remotely...

Crash FrontPage Remotely...


Narr0w (Narr0wTHEHACKERS.COM)
Sat, 7 Aug 1999 15:03:32 +0300


Hello BugTraq friends,
Sorry if it was already in bugtraq, but:

FrontPage PWD32/3.0.2.926 for Win'XX crashes when the url is 167+ long.
I tested it only on: Windows'95 FrontPage Server Extensions Version:
3.0.2.926 Version: FrontPage-PWS32/3.0.2.926.

Here is the error message:

VHTTPD32 caused an invalid page fault in
module VHTTPD32.EXE at 0137:0040aaed.
Registers:
EAX=010d7740 CS=0137 EIP=0040aaed EFLGS=00010202
EBX=00000000 SS=013f ESP=010d53d0 EBP=010d0074
ECX=010d7740 DS=013f ESI=010d7740 FS=13c7
EDX=000000a8 ES=013f EDI=bff92ac1 GS=0000
Bytes at CS:EIP:
ff 75 10 56 68 94 01 00 00 eb 1c 68 00 24 40 00
Stack dump:
00000010 010d7740 00000000 00000000 00000000
00000000 00000000 00000000 00000000 00000000
00000000 00000000 00000000 00000000 00000000
00000000

I attached an perl script that connects to the host & sends 167 long url.

Narr0w


  • application/octet-stream attachment: DoS.zip



This archive was generated by hypermail 2.0b3 on Mon Aug 09 1999 - 09:08:55 CDT