Preface: HTTP GET data overflowLogo -Internet Security Systems

HTTP GET data overflow

advICE :Intrusions : 2000608
 FAQ
Oh my gosh, I'm being HACKED!!!
How do I report the hacker to my ISP?
I'm seeing lots of attacks, is this normal?
Summary

Possible intrusion.

Details

A URL containing a very long data string has been seen. On some Web servers, this may indicate an intrusion attempt.

 more information
CERT: CA-97.24.Count_cgi   Buffer Overrun Vulnerability in Count.cgi cgi-bin Program
A discussion of this bug in relation to a vulnerable CGI program that can be hacked.  
advICE: Buffer overflows  
More about this general class of attacks, which is the root cause of many attacks on the Internet.  
BugtraqID: 128   Count.cgi (wwwcount) Buffer Overflow Vulnerability
 
BugtraqID: 874   Infoseek Ultraseek GET Buffer Overflow Vulnerability
 
BugtraqID: 889   ZBSoft ZBServer GET Buffer Overflow Vulnerability
 
BugtraqID: 905   CamShot GET Buffer Overflow Vulnerability
 
BugtraqID: 908   Netscape FastTrack Server GET Buffer Overflow Vulnerability
 
BugtraqID: 1167   L-Soft Listserv 1.8 Web Archives Buffer Overflow Vulnerability
 
BugtraqID: 1355   Small HTTP Server Buffer Overflow Vulnerability
 
BugtraqID: 1492   O'Reilly WebSite GET Buffer Overflow Vulnerability
 
BugtraqID: 1490   L-Soft Listserv 1.8c and 1.8d Web Archives Long QUERY_STRING Buffer Overflow Vulnerability
 
BugtraqID: 1657   Mobius DocumentDirect for the Internet 1.2 Buffer Overflow Vulnerabilities
 
CVE-1999-0021   Count.cgi
 
CVE-2000-0011   Buffer overflow in AnalogX SimpleServer:WWW HTTP
 
NAI Advisory: 042   LISTSERV Web Archive Remote Overflow
 
NAI Advisory: 043   O'Reilly WebSite Professional Overflow
 

 parametric information
lengthThe length of the GET data; if it is longer than 4000 characters, then it may be a buffer overflow attempt.
URLThe URL.

 configuration for this item
http.maxget1023The maximum length of the GET data after the GET? command.

 
Version appeared:  

Privacy Policy |  Copyright Info