Security Incidents mailing list archives

Re: Found this in my logs


From: H D Moore <hdm () SECUREAUSTIN COM>
Date: Sun, 6 May 2001 16:16:05 -0500

The only scanner I know of that checks mem_bin for the unicode exploit it
nessus:

http://cvs.nessus.org/cgi-bin/cvsweb.cgi/~checkout~/nessus-plugins/scripts/iis_dir_traversal.nasl

-HD

On Monday 30 April 2001 01:05 pm, Hamid T Ouyachchi wrote:
Hello all,

Found this in my IIS logs. I recognize the Unicode exploit attempts,
frontpage msdacs stuff. But what is the /mem-bin/ entry about ?

Hamid Ouyachi
Contractor
Office of Workforce Security
Phone: (202)219-5935 x302


Current thread: