Mailing List Archive

Re: no404 and PNG (image) returning from web site
"Noam Rathaus" <noamr@beyondsecurity.com> writes:

> I came across a false positive generating server, the server will return a
> picture (that changes) for whatever request you give it. It seems that no404
> is not able to handle this. Here is an example:
[snip]

What does the server answer look like?
Re: no404 and PNG (image) returning from web site [ In reply to ]
"Noam Rathaus" <noamr@beyondsecurity.com> writes:

> I mistakenly forgot to provide the response? No I didn't the response has
> "." in it... cause some sendmail/qmail to regard it as end of message.. (Bad
> idea no?)

The HTTP headers are missing :-\
Re: no404 and PNG (image) returning from web site [ In reply to ]
Hi,

I mistakenly forgot to provide the response? No I didn't the response has
"." in it... cause some sendmail/qmail to regard it as end of message.. (Bad
idea no?)

Here it is again (> is to stop this from recurring, it is not in the
response)
> GET /cgi-bin/nessus_is_probing_you_722269810 HTTP/1.1.
> Connection: Close.
> Host: host:8080.
> Pragma: no-cache.
> User-Agent: Mozilla/4.75 [en] (X11, U; Nessus).
> Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png,
*/*.
> Accept-Language: en.
> Accept-Charset: iso-8859-1,*,utf-8.
> .
>
> response: .PNG.
> .
>
....IHDR...............4V...3PLTE............................??.//.OO.......
>
...oo.__..~.....IDATx..W...(.......5.....n.f...-....r.lh.~.......e.w7.j....d
>
.......t..p.../@:>.,..>...9....m.D...w....fZ..V`&...Zp.....(U.)d.Q.f.'r.l.(.
>
..tV.q..R...wd}.....8...].....:.*=.7..&..r...a..r..k.(...../E.e}.......u../.
> ..o..PiH;..u.-(...4.=.{..C.....u..O.&.n.Za.0..7|N..(1.y|q...
> ....[t..
>
..-!...!.....{X..)/.[.....y-..o.r...s_.`.X..z..N=Rm.m.....i..Z.....W...Y...R
> Ml.W.U..t... .e.#.".._....c..v."j.[>
>
.[.E.[e.+L3.Z./..G;.a.Dr$...$]%....{......"?.|.ZAT....^*..:ch.R...&L]...]..S
>
..6.....).L.pR.Qpk.r+E.Yz.L..o..U"..#qL....{E..L..6..3..wE;.....>l.9.b.?=.Z.
> @.D.~..v...T.[!..C.......k...$..S...t.R...b-..M...Z...`F..|
>
[..#......"...._..a....M..;......I.t..JEc..|....B..Kv.Z..E.X...K.r..`..qS...
> ..IK.(.G....}M.FW.H..TO..r....jf]$a5....U.....f.S:..C1......b..W....dV?.
> ]....p...AM...4qt.J.lHtB.5..
>
..$.(.g8..[I.7P.....q....T8.f.L.h^@K?...u.l.x.<........q.{.B[0Q.h.9.j'....5.
> ..oT.. .J.......
>
..Xg.7m.7..I.&q=....i....)..D.9r].i...}...s3.g}<..as.q.O....=b....#_k....9#.
> .+.}.c......7...o...7Q.......e -...W....IEND.B`.....

Thanks
Noam Rathaus
CTO
Beyond Security Ltd.
http://www.BeyondSecurity.com
http://www.SecuriTeam.com

----- Original Message -----
From: "Michel Arboi" <arboi@noos.fr>
To: "Nessus Mailing List" <nessus@list.nessus.org>; "Nessus Plugins Writers"
<plugins-writers@list.nessus.org>
Sent: Wednesday, July 17, 2002 09:42
Subject: Re: no404 and PNG (image) returning from web site


> "Noam Rathaus" <noamr@beyondsecurity.com> writes:
>
> > I came across a false positive generating server, the server will return
a
> > picture (that changes) for whatever request you give it. It seems that
no404
> > is not able to handle this. Here is an example:
> [snip]
>
> What does the server answer look like?
>
>
Re: no404 and PNG (image) returning from web site [ In reply to ]
Hi,

Sorry (Of course this is returned FOR EVERY URL you request).:
Here they are:
> HTTP/1.1 200 OK.
> Server: MegaTime Chart Server.
> Date: Wed, 17 Jul 2002 08:51:03 GMT.
> Content-Type: image/png.
> Content-Length: 1110.
> .
> .PNG.
> .
>
....IHDR...............4V...3PLTE............................??.//.OO.......
...oo.__..~.....IDATx..W...(.......5.....n.f...->
....r.lh.~.......e.w7.j....d.......t..p.../@:>.,..>...9....m.D...w....fZ..V`
&...Zp.....(U.)d.Q.f.'r.l.
>
(...tV.q..R...wd}.....8...].....:.*=.7..&..r...a..r..k.(...../E.e}.......u..
/...o..PiH;..u.-(...4.=.{..C.....u..O.&.n.Za.0..7|N..(1.y|q...
> ....[t..
..-!...!.....{X..)/.[.....y-..o.r...s_.`.X..z..N=Rm.m.....i..Z.....W...Y...R
Ml.W.U..t... .e.#.".._....c..v."j.[>
>
.[.E.[e.+L3.Z./..G;.a.Dr$...$]%....{......"?.|.ZAT....^*..:ch.R...&L]...]..S
..6.....).L.pR.Qpk.r+E.Yz.L..o..U"..#qL....
>
{E..L..6..3..wE;.....>l.9.b.?=.Z.@.D.~..v...T.[!..C.......k...$..S...t.R...b
-..M...Z...`F..|
>
[..#......"...._..a....M..;......I.t..JEc..|....B..Kv.Z..E.X...K.r..`..qS...
..IK.(.G....}M.FW.H..TO..r....jf]
> $a5....U.....f.S:..C1......b..W....dV?.
> ]....p...AM...4qt.J.lHtB.5..
..$.(.g8..[I.7P.....q....T8.f.L.h^@K?...u.l.x.<........q.{.B[0Q.h.9.j'....5.
..oT.. .J....... >
..Xg.7m.7..I.&q=....i....)..D.9r].i...}...s3.g}<..as.q.O....=b....#_k....9#.
.+.}.c......7...o...7Q.......e -...W....IEND.B`.....

Thanks
Noam Rathaus
CTO
Beyond Security Ltd.
http://www.BeyondSecurity.com
http://www.SecuriTeam.com

----- Original Message -----
From: "Michel Arboi" <arboi@noos.fr>
To: "Nessus Mailing List" <nessus@list.nessus.org>; "Nessus Plugins Writers"
<plugins-writers@list.nessus.org>
Sent: Wednesday, July 17, 2002 10:44
Subject: Re: no404 and PNG (image) returning from web site


> "Noam Rathaus" <noamr@beyondsecurity.com> writes:
>
> > I mistakenly forgot to provide the response? No I didn't the response
has
> > "." in it... cause some sendmail/qmail to regard it as end of message..
(Bad
> > idea no?)
>
> The HTTP headers are missing :-\
>