OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
RE: [ISSForum] HTTP_1_1_Chunked_Encoding_Transfer

From: Palmer, Paul (ISSAtlanta) (PPalmeriss.net)
Date: Thu May 27 2004 - 08:04:57 CDT


German,

We likely do detect that "event" with one of our existing signatures as we have many signatures for various vulnerabilities related to chunked encoding:

HTTP_IIS_ASP_Chunked_Overflow
HTTP_IIS_Media_Services
ASP_Chunked_Overflow
HTTP_Apache_Chunked_BO
HTTP_Apache_Chunked_DoS
HTTP_IIS_HTR_Chunked_Overflow
HTTP_IIS_FPSE_Debug_Bo

Do you know which exploit triggers this other IDS's event or do you know the CVE number to which this event corresponds?

Paul

-----Original Message-----
From: issforum-bouncesatla-mm1.iss.net On Behalf Of German A Suarez Nahon
Sent: Tuesday, May 25, 2004 8:52 AM
To: issforumatla-mm1.iss.net
Subject: [ISSForum] HTTP_1_1_Chunked_Encoding_Transfer
Importance: High

Hi everyone...

      Anybody know this "attack"? We have another IDS services and they can
detec that event. My question is ¿Why not our Network Sensors?

Saludos....
Germán Alberto Suárez Nahón
Banco Mercantil CA SACA
Seguridad de la Información
Phone: 58 212 5030270 / 0026 (Fax)
http://www.bancomercantil.com
mailto:german_suarezbancomercantil.com

_______________________________________________
ISSForum mailing list
ISSForumiss.net

TO UNSUBSCRIBE OR CHANGE YOUR SUBSCRIPTION, go to https://atla-mm1.iss.net/mailman/listinfo/issforum

To contact the ISSForum Moderator, send email to mod-issforumiss.net

The ISSForum mailing list is hosted and managed by Internet Security Systems, 6303 Barfield Road, Atlanta, Georgia, USA 30328.

_______________________________________________
ISSForum mailing list
ISSForumiss.net

TO UNSUBSCRIBE OR CHANGE YOUR SUBSCRIPTION, go to https://atla-mm1.iss.net/mailman/listinfo/issforum

To contact the ISSForum Moderator, send email to mod-issforumiss.net

The ISSForum mailing list is hosted and managed by Internet Security Systems, 6303 Barfield Road, Atlanta, Georgia, USA 30328.