Plugin ID | 10 |
Plugin name | TinyWeb 1.9 Denial of Service |
Plugin filename | TinyWeb 1.9 Denial of Service.plugin |
Plugin filesize | 2473 bytes |
Plugin family | HTTP |
Plugin created name | Marc Ruef |
Plugin created email | marc dot ruef at computec dot ch |
Plugin created web | http://www.computec.ch |
Plugin created company | computec.ch |
Plugin created date | 2003/11/13 |
Plugin updated name | Marc Ruef |
Plugin updated email | marc dot ruef at computec dot ch |
Plugin updated web | http://www.computec.ch |
Plugin updated company | computec.ch |
Plugin updated date | 2004/11/13 |
Plugin version | 2.0 |
Plugin changelog | Corrected the plugin structure and added the accuracy values in 1.1. Improved the pattern matching and added the changelog in 2.0 |
Plugin protocol | tcp |
Plugin port | 80 |
Plugin procedure detection | open|send HEAD / HTTP/1.0\n\n|sleep|close|pattern_exists HTTP/#.# ### *TinyWeb 1.* |
Plugin detection accuracy | 80 |
Plugin comment | Thanks to Armin Pelkham for pointing out some errors in the sources links. |
Bug affected | TinyWeb server before 1.9 |
Bug not affected | Other web servers and TinyWeb newer than 1.9. |
Bug vulnerability class | Denial Of Service |
Bug description | The remote host is running TinyWeb version 1.9 or older. A remote user can issue an HTTP GET request for /cgi-bin/.%00./dddd.html and cause the server consume large amounts of CPU time (88%-92%). |
Bug solution | Upgrade to the latest version. Contact vendor http://www.ritlabs.com. |
Bug fixing time | 20 minutes |
Bug exploit availability | Yes |
Bug remote | Yes |
Bug local | Yes |
Bug severity | High |
Bug popularity | 6 |
Bug simplicity | 6 |
Bug impact | 8 |
Bug risk | 6 |
Source Literature | Hacking Exposed: Network Security Secrets & Solutions, Stuart McClure, Joel Scambray and George Kurtz, February 25, 2003, 4th Edition, McGraw-Hill Osborne Media, ISBN 0072227427 |
Source Misc. | http://www.computec.ch |