[18298] in bugtraq

home help back first fref pref prev next nref lref last post

Re: Infinite InterChange DoS

daemon@ATHENA.MIT.EDU (SNS Research)
Thu Dec 21 19:59:25 2000

Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Message-Id:  <3021234723.20001221203537@greyhack.com>
Date:         Thu, 21 Dec 2000 20:35:37 +0100
Reply-To: SNS Research <vuln-dev@greyhack.com>
From: SNS Research <vuln-dev@GREYHACK.COM>
To: BUGTRAQ@SECURITYFOCUS.COM
In-Reply-To:  <1049930519.20001221172712@greyhack.com>

Obviously there's a typo in the example contained in our previous
post, no matter how hard you try a POST is not a GET.

Correct execution would be

telnet victim 80
POST (963+ bytes) HTTP/1.0

Sorry for the inconvience, where is the world coming to if advisories
contain bugs eh?

Scsi-bear
SNS Research

~ this had nothing to do with the other bug being not reproducable btw
:P

home help back first fref pref prev next nref lref last post