Preface: HTTP Authentication overflowLogo -Internet Security Systems

HTTP Authentication overflow

advICE :Intrusions : 2000622
 FAQ
Oh my gosh, I'm being HACKED!!!
How do I report the hacker to my ISP?
I'm seeing lots of attacks, is this normal?
Summary

The attacker may be attempting to break into a server by sending an HTTP Authentication string containing many characters.

Details

Some web servers require logins in order to access the content. This is especially true for applications servers and web servers that allow remote administration.

Even though hackers might not know the correct username or password, they can try to specify ones that are longer than the system can handle. In such a way, they may trigger a "buffer oveflow", which would allow them to execute their own code on the server.

 more information
BugtraqID: 1685   CamShot Remote Buffer Overflow Vulnerability
Some versions of this software contain a buffer overflow.  
BugtraqID: 876   SCO Unixware i2odialogd Remote Buffer Overflow Vulnerability
i2odialogd is shipped with SCO Unixware and installed running as root by default. In its authentication mechanism exists a serious buffer overflow vulnerability. By default it runs at TCP port 360.  
BugtraqID: 865   Netscape Enterprise Server for NetWare Admin Buffer Overflow Vulnerability
The server for NetWare 4/5 includes an Admin feature that is vulnerable to denial of service attacks  
BugtraqID: 847   Netscape Enterprise & FastTrack Authentication Buffer Overflow Vulnerability
Root privileges can be gained with a username or password of more than 508 characters.  
BugtraqID: 767   Real Server Administrator Port Buffer Overflow Vulnerability
The server for streaming RealAudio contains a remote web administration facility that can be exploited in this manner.  
CVE-2000-0417   Cayman 3220-H DSL router allows remote DoS via long username or password
 
CVE-2000-0026   UnixWare i2odialogd overflow in username/password authorization
 
CVE-1999-0853   Buffer overflow in Netscape Enterprise Server and Server HTTP Basic Authentication procedure.
 
CVE-1999-0896   Buffer overflow in RealNetworks RealServer via a long username and password.
 
advICE: Buffer overflows  
More about this general class of attacks, which is the root cause of many attacks on the Internet.  
 
Version appeared: 1.9 

Privacy Policy |  Copyright Info