Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: AToZed Software Intraweb Component for Borland Delphi and Kylix DoS vulnerability |
|---|---|
| Date: | Thu, 25 Jan 2007 07:39:03 +0100 |
Please look at Olaf's blog at AToZed to decide if the bug was fake or real!
http://blogs.atozed.com/Olaf/
C0r31mp4ct
Type: Deniel of Service Severity: Critical Title: AToZed Software IntraWeb Component for Borland Delphi and Kylix DoS vulnerability Date: January 23, 2007
Synopsys --------
A DoS vulnerability exists in the IntraWeb Component of AToZed Software.
Background ---------
IntraWeb is a RAD component for Borland Delphi and Kylix by AToZed Software, which allows developers to rapidly develop webapplication. This component is commonly used by Borland developers internationally.
Description -----------
DoS conditions occurs, when a specially crafted HTTP request is sent to the webapplication. After the request, the affected thread enters into an infinte loop, and hangs. Under IIS 5.x, the thread will never be stopped. Under IIS 6 the webserver automatically stops the thread after the configured amount of time, or CPU usage.
Impact ------
An attack can cause the webapplication to slow down, and after more specially crafted request, to stop processing requests.
WorkAround ----------
There is no vendor supplied workaround for the problem at this time.
A possible workaround can be, to filter the request body for the special request, and repair it. It can be achieved, by overriding the function called "OnBeforeDispatch" of the TIWServerController object, and repair the request, by changing the "Request.Content" field.
Affected versions -----------------
IntraWeb 8.0 and lower versions
Vulnerability timeline ----------------------
2006.08. - Vendor notified, but no answer 2007.01.23 - Vulnerability publicly available
Discovery is credited to: C0r31mp4ct
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Omniture SiteCatalyst Multiple Cross-Site Scripting Vulnerabilities, DoZ |
|---|---|
| Next by Date: | Re: ZixForum <= 1.14 (Zixforum.mdb) Remote Password Disclosure Vulnerability, anonym |
| Previous by Thread: | AToZed Software Intraweb Component for Borland Delphi and Kylix DoS vulnerability, C0r3 1mp4ct |
| Next by Thread: | Re: AToZed Software Intraweb Component for Borland Delphi and Kylix DoS vulnerability, mail |
| Indexes: | [Date] [Thread] [Top] [All Lists] |