A Microsoft-discovered buffer overrun vulnerability in IIS 4.0, 5.0 and 5.1 that results from an error in safety check that is performed during server-side includes. In some cases, a user request for a web page is properly processed by including the file into an ASP script and processing it. Prior to processing the include request, IIS performs an operation on the user-specified file name, designed to ensure that the file name is valid and sized appropriately to fit in a static buffer. However, in some cases it could be possible to provide a bogus, extremely long file name in a way that would pass the safety check, thereby resulting in a buffer overrun.作者: snhao 时间: 2009-11-27 11:38 呵呵,干上了,来看戏。作者: kkk03 时间: 2009-11-29 10:57 到底要说啥?作者: lsj301 时间: 2009-11-29 23:04 两个黄鹂鸣翠柳-----我等菜鸟知所云?
[ Last edited by lsj301 on 2009-11-29 at 23:06 ]作者: 专业路过 时间: 2009-11-30 00:19 南北信源的确还是很了不起的