发新话题
打印

[转载]Savant Web服务器URI缓冲区溢出

[转载]Savant Web服务器URI缓冲区溢出

文章作者:Mati Aharoni

Summary
Savant is "a full-featured open source web server for computers running any version of Windows 95/NT or greater".

Due to improper bounds checking routines in Savant, a remote attacker can cause the program to overflow an internal buffer and as a consequence execute arbitrary code.

Credit:
The information has been provided by Mati Aharoni.

Details
Vulnerable Systems:
* Savant Web Server version 3.1 and prior

By sending a malformed HTTP request in the following format Any_Text / [256 Bytes]\r\n a remote attacker is able to overwrite the instruction pointer with an arbitrary address.

Exploit:
http://www.eviloctal.com/forum/read.php?tid=7476
曾几何时,有人对我说:装B遭雷劈。我说:去你妈的。于是,这个人又对我说:如果再说脏话,上帝会惩罚你的。我说:我操上帝。结论:彪悍的人生不需要上帝。

TOP

发新话题