Microsoft IIS Malformed HTTP HOST Header Field Denial Of Service Vulnerability
BID:5907
Info
Microsoft IIS Malformed HTTP HOST Header Field Denial Of Service Vulnerability
| Bugtraq ID: | 5907 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 07 2002 12:00AM |
| Updated: | Oct 07 2002 12:00AM |
| Credit: | This issue was discovered during a default run of Spike 2.7 by Dave Aitel <[email protected]>. |
| Vulnerable: |
Microsoft IIS 5.1 Microsoft IIS 5.0 |
| Not Vulnerable: | |
Discussion
Microsoft IIS Malformed HTTP HOST Header Field Denial Of Service Vulnerability
Microsoft IIS is reported to be prone to a remotely exploitable denial of service.
This condition occurs upon receipt of a malformed HOST field in a HTTP request for 'shtml.dll'. It is possible to reproduce this condition by sending a HTTP POST request with a HOST header field that is composed of an excessive number of slashes (/).
Further details are not known at this time.
Microsoft IIS is reported to be prone to a remotely exploitable denial of service.
This condition occurs upon receipt of a malformed HOST field in a HTTP request for 'shtml.dll'. It is possible to reproduce this condition by sending a HTTP POST request with a HOST header field that is composed of an excessive number of slashes (/).
Further details are not known at this time.
Exploit / POC
Microsoft IIS Malformed HTTP HOST Header Field Denial Of Service Vulnerability
This vulnerability was discovered during a default run of SPIKE 2.7. A proof-of-concept screenshot can be found at the following location:
http://www.immunitysec.com/inetinfo_spin.jpg
This vulnerability was discovered during a default run of SPIKE 2.7. A proof-of-concept screenshot can be found at the following location:
http://www.immunitysec.com/inetinfo_spin.jpg
References
Microsoft IIS Malformed HTTP HOST Header Field Denial Of Service Vulnerability
References:
References:
- SPIKE Homepage (Immunity, Inc.)