Microsoft IIS False Logging Weakness
BID:6795
Info
Microsoft IIS False Logging Weakness
| Bugtraq ID: | 6795 |
| Class: | Input Validation Error |
| CVE: |
CVE-2001-0902 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 19 2001 12:00AM |
| Updated: | Jul 11 2009 08:06PM |
| Credit: | Discovery credited to [email protected]. |
| Vulnerable: |
Microsoft IIS 5.0 Microsoft IIS 4.0 Microsoft IIS 3.0 |
| Not Vulnerable: | |
Discussion
Microsoft IIS False Logging Weakness
A weakness in the reporting functionality of Microsoft IIS has been discovered.
It is possible to cause IIS to log false information. This problem occurs when an attacker makes a HTTP request using hexadecimal encoded requests.
A malicious attacker can cause IIS to fill the log with false information. This may result in confusion when other services make use of the false IIS log data.
It should be noted that this issue highly depends on the text editor used to analyze the logs. Some hexadecimal sequences may have varying results when interpreted.
A weakness in the reporting functionality of Microsoft IIS has been discovered.
It is possible to cause IIS to log false information. This problem occurs when an attacker makes a HTTP request using hexadecimal encoded requests.
A malicious attacker can cause IIS to fill the log with false information. This may result in confusion when other services make use of the false IIS log data.
It should be noted that this issue highly depends on the text editor used to analyze the logs. Some hexadecimal sequences may have varying results when interpreted.
Exploit / POC
Microsoft IIS False Logging Weakness
There is no exploit required.
There is no exploit required.
Solution / Fix
Microsoft IIS False Logging Weakness
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft IIS False Logging Weakness
References:
References: