Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Improvements on MS15-034 #15442

Open
wants to merge 1 commit into
base: develop
Choose a base branch
from
Open

Improvements on MS15-034 #15442

wants to merge 1 commit into from

Conversation

oguzhantopgul
Copy link

This PR tries to address false-negatives and unintentional Denial of Service

  • Requesting non-image files might result false-negatives. Let's request image files for better detection.

"Requesting non-image files was hit-or-miss with the server often responding with a connection reset."
quoted from http://www.securitysift.com/an-analysis-of-ms15-034/

  • Additionally bytes=18-18446744073709551615 as Range value most probably results DoS in vulnerable servers. Range with bytes=0-18446744073709551615 is more safer for detection.

Please let me know what do you think about this update?

…est image files for better detection.

* Additionally bytes=18-18446744073709551615 as Range value most probably results DoS in vulnerable servers. Range with bytes=0-18446744073709551615 is more safer for detection.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant