|
|
|
Date Submitted:
06/17/05
Hits: 32 Rating: ![]() ![]() ![]() ![]() based on 0 votes
Blind Buffer Overflows In ISAPI ExtensionsAdded by Papergrl
Description:
In this paper we will use different ISAPI extension on a Microsoft Windows 2000, Internet Information Server (IIS) 5.0 web server. A number of different ISAPI extensions were created, each with a different type of stack-based overflow vulnerability to act as demonstrative proprietary applications as seen in the wild. The following examples are overflows using strcpy(), sprintf(), and strcat(). A second set of extensions had also been built with the Microsoft Visual Studio .NET stack protection enabled (/GS option) [ref 2]. The author will demonstrate how to bypass these protection mechanisms and execute arbitrary code completely blind.
Read the Complete Paper You don't have permission to post replies. Please login or register. |
