WebApp Sec mailing list archives

[Fwd: Re: URL Scan for IIS]


From: Mark Curphey <mark () curphey com>
Date: 23 Feb 2003 20:47:36 -0800

Some posts seem to be getting dropped (or getting queued weirdly) ....I
logged it with securityfocus....if your post doesn't get though within
24 hours please resubmit it and CC me. Thanks.

--- Begin Message --- From: Dave Aitel <dave () immunitysec com>
Date: Sun, 23 Feb 2003 23:00:15 -0500

It's highly effective against URL and Header overflows - of which the
most recent is probably the ColdFusion/JRun overflow.

It's not effective at all at many overflows that Microsoft says it is
effective at preventing - the ones that occur in the body arguments.
Some examples include the MSADC overflow, and the Microsoft Content
Server authentication overflow.

I'll be doing a more specific demo of one of those next week at BlackHat
in Seattle. Stop on by. :>

Dave Aitel
Immunity, Inc.
http://www.immunitysec.com/CANVAS/ 

On Sat, 22 Feb 2003 20:55:19 -0800
securityarchitect () hush com wrote:


I just took a lok at URL Scan and wondered if anyone has any comments
as to its effectiveness ?

Also does anyone have a decent urlscan ini file of additional strings
they are filtering that would share for education ?



Concerned about your privacy? Follow this link to get
FREE encrypted email: https://www.hushmail.com/?l=2 

Big $$$ to be made with the HushMail Affiliate Program: 
https://www.hushmail.com/about.php?subloc=affiliate&l=427



--- End Message ---

Current thread: