OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: H. Morrow Long (morrow.longYALE.EDU)
Date: Thu Aug 30 2001 - 10:55:18 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    This is documented in a May 1, 2001 Microsoft Security Bulletin MS01-023, see:

      "Unchecked Buffer in ISAPI Extension Could Enable Compromise of IIS 5.0 Server".
      http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS01-023.asp

      "Remote IIS ISAPI Printer Extension Buffer Overflow"
      http://xforce.iss.net/alerts/advise75.php#list

      The Snort IDS has a check for this called:

            IDS533/web-iis_http-iis5-printer-isapi

    - H. Morrow Long

      Originally posted: May 01, 2001

    Gabor Tokaji wrote:
    >
    > does anybody know of a new worm taking rounds out there? I keep getting
    >
    > 2001-08-23 16:37:51 x.x.x.x - x.x.x.x 80 GET /NULL.printer - 404 -
    >
    > requests more and more often. It begun a couple of days ago. All machines
    > sending these to mine are win2k machines. doesn't look like kids probing -
    > it looks more organized.
    >
    > G.
    >
    > _____________________________________________________________________
    > ** TO UNSUBSCRIBE, send the command "UNSUBSCRIBE win2ksecadvice"
    > ** FOR A WEEKLY DIGEST, send the command "SET win2ksecadvice DIGEST"
    > SEND ALL COMMANDS TO: listservlistserv.ntsecurity.net


    _____________________________________________________________________
    ** TO UNSUBSCRIBE, send the command "UNSUBSCRIBE win2ksecadvice"
    ** FOR A WEEKLY DIGEST, send the command "SET win2ksecadvice DIGEST"
    SEND ALL COMMANDS TO: listservlistserv.ntsecurity.net