[25023] in bugtraq

home help back first fref pref prev next nref lref last post

SPIKE version released that detects .HTR and ISAPI overflows (see

daemon@ATHENA.MIT.EDU (Dave Aitel)
Wed Apr 10 16:48:03 2002

Message-ID: <3CB45922.24DB20B8@atstake.com>
Date: Wed, 10 Apr 2002 11:24:18 -0400
From: Dave Aitel <daitel@atstake.com>
MIME-Version: 1.0
To: bugtraq@securityfocus.com
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit

At long last, SPIKE is once again allowed to be public. This is the
fuzzer creation kit I wrote that finds the .HTR and ISAPI overflow
vulnerabilities discussed here:
http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS02-018.asp
and
here: http://www.atstake.com/research/advisories
(The Microsoft advisory currently misattributes this vulnerability to
Chris Wysopal instead of me :<.)

Anyways, the new SPIKE is available (in source code form only) from
spike.sourceforge.net, as is the rather extensive Changelog. It's pretty
useful for generic web app auditing as well now.

Yes, SPIKE is still GPL.

Dave Aitel



home help back first fref pref prev next nref lref last post