Savant Web Server v2.0 Local/Remote DoS attack (Win95/98/NT/2K)

Local / Remote D.o.S Attack in Savant Web Server V2.0 WIN9X / NT / 2K

USSR Advisory Code:   USSR-99026

Release Date:
December 28, 1999 [2/5]

Systems Affected:
Savant Web Server V2.0 Win9X / NT / 2K and possibly others versions.

About The Software:
Savant provides support for most modern web features and technologies,

Common Gateway Interface (CGI) 1.0 and 1.1
HTTP 0.9, 1.0, and 1.1 including keep-alive ability
Comprehensive logging in the standard NCSA format
User and group management
Password protection
Server-side image maps
Support for over 40 file types, including MP3, RealAudio, and Microsoft
Office files
XML, JavaScript, Java, and ActiveX, and more!


UssrLabs found a Local / Remote Buffer overflow,the buffer overflow is
caused by a NULL Character in the parsing Get Command rutine.

in Internet Explorer, address: Htpp://SavantServerIP/%00/

The D.O.S action is logged in, C:\Savant\Logs\general.txt, inside looks like
this one

Attacker Ip - - [20/Dec/1999:00:10:27 -0300] "GET
htmlindex.htmlindex.htmlindex.htmlindex.htmlindex.htmlindex.html" 301 279

Vendor Status:

Vendor   Url:
Program Url:


Noting yet :(

