Hi all

while scanning a remote client machine. I got a
security hole as 
"We could crash the Savant web server by sending an
invalid
GET HTTP request with a negative Content-Length field.

A cracker may exploit this flaw to disable your
service or
even execute arbitrary code on your system."

I verified this by running
"savant_content_length_DoS.nasl" standalone and this
didn't say attack to be successfull.

And the remote web server is IIS 5.0 .

Any clues?

Regards,
Bishan

________________________________________________________________________
Want to chat instantly with your online friends?  Get the FREE Yahoo!
Messenger http://uk.messenger.yahoo.com/

Reply via email to