Bugtraq mailing list archives
SPIKE version released that detects .HTR and ISAPI overflows (see spike.sourceforge.net)
From: Dave Aitel <daitel () atstake com>
Date: Wed, 10 Apr 2002 11:24:18 -0400
At long last, SPIKE is once again allowed to be public. This is the fuzzer creation kit I wrote that finds the .HTR and ISAPI overflow vulnerabilities discussed here: http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS02-018.asp and here: http://www.atstake.com/research/advisories (The Microsoft advisory currently misattributes this vulnerability to Chris Wysopal instead of me :<.) Anyways, the new SPIKE is available (in source code form only) from spike.sourceforge.net, as is the rather extensive Changelog. It's pretty useful for generic web app auditing as well now. Yes, SPIKE is still GPL. Dave Aitel
Current thread:
- SPIKE version released that detects .HTR and ISAPI overflows (see spike.sourceforge.net) Dave Aitel (Apr 10)