Ads

Fastream NETFile FTP/Web Server HTTP HEAD DoS PDF Print E-mail
Saturday, 10 September 2005
Summary
"Fastream NETFile FTP/Web Server is a secure FTP server and Web-based file server combined together in one program. Our claim is that it is the "easiest to setup and administer server" on the Internet!"

Due to improper handling of keepalive in HTTP HEAD requests, it is possible to cause a denial of service to Fastream NETFile FTP/Web Server. Credit:
The information has been provided by bratax ck.

Details
Vulnerable Systems:
* Fastream NETFile FTP/Web Server 7.1.2 Professional

Fastream NETfile FTP/Web Server improperly handles the timeout on "keepalive" connections after making a HEAD request to the web server. When a remote user sends a HEAD request, the web server doesnt close the connection with the client. This makes it possible for a remote user to use all the available connections and thus make the software deny service to other users.
 
< Prev   Next >