Snitz Forums 2000
Snitz Forums 2000
Home | Profile | Register | Active Topics | Members | Search | FAQ
Username:
Password:
Save Password
Forgot your Password?

 All Forums
 Help Groups for Snitz Forums 2000 Users
 Help: General / Current Version (Old)
 Help! Shell command injection attempt detected
 New Topic  Topic Locked
 Printer Friendly
Previous Page
Author Previous Topic Topic Next Topic
Page: of 2

Stevensan
Starting Member

38 Posts

Posted - 01 November 2007 :  20:51:30  Show Profile
Well then. Thanks for the support of you guys my network administrator has not gotten back to me with my questions on the intrusion detection system. :)

Snitz Forum 3.4 + PM + Poll + Avatar + Message Icon + Gender + Hover Color + CellBGImage + Additional Smilies + ActiveUser Mod
Go to Top of Page

Stevensan
Starting Member

38 Posts

Posted - 08 November 2007 :  20:16:33  Show Profile
Can anyone advise me on this? What should i do? I was informed by my network administrator of this security vulunerability. The details are as follows:

HTML_Hostname_Overflow alert detected on Forum.asp

Time: 2007-11-05 00:56:37 GMT
Tag Name: HTML_Hostname_Overflow
Event Count: 1 (Total of 19 count)
Severity: High
Source IP: xx.xx.xx.aa
Target IP: xx.xx.xx.bb (4 different Target IP detected)
Server: Intranet.xxxx
Packet SourcePort: 80
Packet DestinationPort: 1210 (Other includes 1858, 1053, 1230, 1229, 2080)
protocol: http
accessed: yes
URL: /FORUM/topic.asp
URI: http://www...arghhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhh





Snitz Forum 3.4 + PM + Poll + Avatar + Message Icon + Gender + Hover Color + CellBGImage + Additional Smilies + ActiveUser Mod
Go to Top of Page

weeweeslap
Senior Member

USA
1077 Posts

Posted - 08 November 2007 :  20:23:33  Show Profile  Visit weeweeslap's Homepage  Send weeweeslap an AOL message  Send weeweeslap a Yahoo! Message
that's not a vulnerability imo, his detection system is just whack.

coaster crazy
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 09 November 2007 :  05:00:52  Show Profile  Send ruirib a Yahoo! Message
Yep... the detection system is plain bad... and the system administrator doesn't even look at what it is outputing.


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page

Stevensan
Starting Member

38 Posts

Posted - 11 November 2007 :  20:37:01  Show Profile
I was bombarded with the document below. -_- so my answer to my network guy would be.
<<You need to upgrade your detection system and based on the content of the post no harm is done.>>

Microsoft Internet Explorer URL buffer overflow (HTML_Hostname_Overflow)
About this signature or vulnerability
Proventia Network IPS, Proventia-G 1.1 and earlier, Proventia Desktop, Proventia Network MFS, Proventia Server IPS for Linux, RealSecure Server Sensor, RealSecure Network, BlackICE PC Protection, BlackICE Agent for Server, BlackICE Server Protection, Proventia Server IPS for Windows:
This signature detects a malicious web page with a very long hostname.
Default risk level
High
..... so on and so forth...

Snitz Forum 3.4 + PM + Poll + Avatar + Message Icon + Gender + Hover Color + CellBGImage + Additional Smilies + ActiveUser Mod

Edited by - Stevensan on 11 November 2007 20:37:40
Go to Top of Page

pdrg
Support Moderator

United Kingdom
2897 Posts

Posted - 12 November 2007 :  09:35:15  Show Profile  Send pdrg a Yahoo! Message
erm - to my knowledge a well service-packed IIS is safe against overflows - I can see how they saw the arghhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhh...etc as an attemnpt at a padded post to push for a buffer overflow though.
Go to Top of Page

Stevensan
Starting Member

38 Posts

Posted - 14 November 2007 :  02:10:11  Show Profile
Thanks for the advise. As long as its not a bug its fine with me. I better upgrade and learn more about all the server stuff... I see more trash coming...

Snitz Forum 3.4 + PM + Poll + Avatar + Message Icon + Gender + Hover Color + CellBGImage + Additional Smilies + ActiveUser Mod
Go to Top of Page

pdrg
Support Moderator

United Kingdom
2897 Posts

Posted - 14 November 2007 :  08:28:31  Show Profile  Send pdrg a Yahoo! Message
Keep us posted if you do get any more 'trash' - you never can tell when something you experience may be a vital clue in a bigger puzzle/whatever!

Thanks :-)
Go to Top of Page
Page: of 2 Previous Topic Topic Next Topic  
Previous Page
 New Topic  Topic Locked
 Printer Friendly
Jump To:
Snitz Forums 2000 © 2000-2021 Snitz™ Communications Go To Top Of Page
This page was generated in 0.23 seconds. Powered By: Snitz Forums 2000 Version 3.4.07