Apache 2.2.14 mod_isapi Dangling Pointer

Apache 2.2.14 mod_isapi Dangling Pointer The Apache HTTP Server, commonly referred to as Apache, is a popular open source web server software. mod_isapi is a core module of the Apache package that implements the Internet Server extension API. The extension allows Apache to serve Internet Server extensions (ISAPI .dll modules) for Microsoft Windows based hosts. By sending a specially crafted request followed by a reset packet it is possible to trigger a vulnerability in Apache mod_isapi that will unload the target ISAPI module from memory. However function pointers still remain in memory and are called when published ISAPI functions are referenced. This results in a dangling pointer vulnerability. Successful exploitation results in the execution of arbitrary code with SYSTEM privileges. www.senseofsecurity.com.au www.senseofsecurity.com.au www.zdnet.com.au
Video Rating: 5 / 5

Revisions

There are no revisions for this post.

Users who found this page were searching for:

  • metasploit mod_isapi
  • apache 2.2.14 mod_isapi
  • apache 2.2.14 mod_isapi exploit "compiled"
  • apache mod_isapi = 2.2.14 dangling pointer
  • mod_isapi exploit use
  • apache mod_isapi dangling pointer
  • apache mod_isapi
  • compile apache 2.2.14 mod_isapi dangling pointer
  • metasploit mod_isapi dangling pointer
  • check to see if sos.txt was created

Tags: , , , , , , , , , , , , , , , , , , ,

9 Responses to “Apache 2.2.14 mod_isapi Dangling Pointer”

  1. TheMarkmsb September 3, 2011 at 8:17 PM #

    What am I doing with these error: Check to see if sos.txt was created

  2. sleeverbr September 3, 2011 at 9:02 PM #

    i get this error “Check to see if sos.txt was created…” ????

  3. harshspiderwebbond September 3, 2011 at 9:55 PM #

    please tell me how to do this using metasploit??

  4. LudakLudi September 3, 2011 at 9:56 PM #

    i get this error “Check to see if sos.txt was created…” ???? what is prob m8 ??

  5. ermal900 September 3, 2011 at 10:54 PM #

    can u give me your compiled exe please?

    Good work! :)

  6. Dragonsol September 3, 2011 at 11:22 PM #

    very few people know and exploit it effectively as this technique is often one of the most complex in the field of computer security.
    Congratulations wertyuiop408

  7. LagartoNET303030 September 4, 2011 at 12:09 AM #

    awesome

  8. writ3r September 4, 2011 at 12:51 AM #

    @EtrenX The video came out before the metasploit module was available.

  9. EtrenX September 4, 2011 at 12:59 AM #

    nice vid, could be a bit more in-depth though.
    what about the Metasploit module?

Leave a Reply