| Forum Home | ||||
| Press F1 | ||||
| Thread ID: 51697 | 2004-11-27 23:06:00 | MS-SQL_NullPacket_DoS | Spacemannz (808) | Press F1 |
| Post ID | Timestamp | Content | User | ||
| 297090 | 2004-11-27 23:06:00 | Is anyone getting this message with Nortons internet security, to do with acvsrv.mediaonenetwork.net the site that loads from PressF1?? By the sounds of what it says on the Symantec site, this message is not good. Attack Category: Denial of Service Severity: High This attack could pose a serious security threat. You should take immediate action to stop any damage or prevent further damage from happening. Description This signature detects an attempt to exploit the NULL byte vulnerability in MS SQL Server. If Microsoft SQL Server 7.0 receives a TDS header with three or more NULL bytes as data, it will crash. The crash will generate an event in the log with ID 17055 "fatal exception EXCEPTION_ACCESS VIOLATION." |
Spacemannz (808) | ||
| 297091 | 2004-11-27 23:08:00 | > Is anyone getting this message with Nortons internet > security, to do with acvsrv.mediaonenetwork.net the > site that loads from PressF1?? Using NIS 2003, I don't get that, or any other, message regarding PressF1. Mike. |
Mike (15) | ||
| 297092 | 2004-11-27 23:11:00 | Yup my NIS 2003 picked it up @ 11.09 this morning. It doesnt say pressf1 in the alert, just the mediaonenetwork.net site that you'll see often when going from page to page on the pressf1 site down the bottom of ie. Where PressF1 gets something loaded from. |
Spacemannz (808) | ||
| 1 | |||||