[14349] in bugtraq
DoS with NAVIEG
daemon@ATHENA.MIT.EDU (PAUL VanDyke)
Mon Mar 20 06:51:56 2000
Mime-Version: 1.0
Content-Type: text/plain; charset=US-ASCII
Content-Disposition: inline
Message-Id: <s8d1f3e3.036@kib.co.kodiak.ak.us>
Date: Fri, 17 Mar 2000 08:59:00 -0900
Reply-To: PAUL VanDyke <pvandyke@KIB.CO.KODIAK.AK.US>
From: PAUL VanDyke <pvandyke@KIB.CO.KODIAK.AK.US>
X-To: BUGTRAQ@SECURITYFOCUS.COM
To: BUGTRAQ@SECURITYFOCUS.COM
Content-Transfer-Encoding: 8bit
When running a Nessus security scan I've discovered that Norton AntiVirus for Internet Email Gateways for Windows NT will crash with an unusually long URL on it's webserver. This service is a SMTP agent used to screen email attachments for viruses. It seems like a great idea, but it uses an embedded webserver to configure the product after install. During the Nessus scan, it has crashed every time rendering the service unavailable with a Doctor Watson screen.
I have not contacted the vendor on this issue.
Paul VanDyke
Network Administrator
Kodiak Island Borough