Full Disclosure mailing list archives

SecurityFocus found a vulnerability in IIS


From: BoneMachine <bonemach () sdf lonestar org>
Date: Wed, 18 Feb 2004 09:38:32 GMT

Hello, 
I was browsing through the findings of SecurityFocus and found the following:
BID 9660 - "Microsoft IIS Unspecified Remote Denial Of Service Vulnerability"

It seems that using an OpenSSL ASN.1 brute force tool IIS 5.0 can be brought to a halt. 

<dramatic>
So ... 
does MS use OpenSSL code?
Has anyone tested this on hosts running a more current version of IIS?
Has anyone used this tool on other "critical apps", VPNs anyone?
Is this tool the holy grail of ASN.1 testing?
Is this tool the cause that eEye has about 7 vulnerabilities waiting to be disclosed?

These are the questions running through my head, bouncing against my scull, searching for an answer.

Is there someone on this list that can help me out?
</dramatic>

greetings
Bone Machine

---
"We're going higher" - The Pixies
---

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: