Netscape Servers Vulnerable to DoS Attack

Netscape Servers running on Windows NT 4.0 are vulnerable to a simple DoS attack.

Steve Manzuik

October 30, 2000

1 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported October 31, 2000 by CORE SDI

VERSIONS AFFECTED

DESCRIPTIONA problem with multiple components of the Netscape Server suite allows a malicious attacker to conduct denial of service attacks on systems running Netscape Server software.  

DEMONSTRATION

By sending the following URL to the listening Directory Services Gateway TCP Port on a server running Netscape Directory Server or Netscape Certificate Management System a malicious user can cause an exception error and the system will stop responding.

http://systemrunningnetscape:24326/dsgw/bin/search?context=%

VENDOR RESPONSE

Unfortunately, Netscape Communications/AOL has been very unresponsive about this issue.  The vendor has been notified by multiple parties but no public response has been given.

CREDITDiscovered by CORE SDI

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like