Vulnerability Development mailing list archives

Re: CodeGreen beta release (idq-patcher/antiCodeRed/etc.)


From: Markus Kern <markus-kern () gmx net>
Date: Fri, 07 Sep 2001 12:39:13 +0200


S wrote:

To the author of CRclean.

It is the tradition here to exploit vulnerabilities. What happens if I send
the code red infect string to the broadcast address of the network segment
of a machine running CRclean?

How do you want to accomplish this? CRclean is running inside IIS and doesn't
monitor the wire like an IDS. The attacker must succesfully complete the TCP
handshake to send a HTTP request.

I like the codegreen idea, but you have to be as careful as those guys in
redmond have to be... did you remember to check the attacking address for
this?

No, the attacking address is not checked at all.
I believe it's not necessary.
 
regards,
Markus Kern


Current thread: