Skip to content

Review - URL-OVERLONG-UTF8 #110

Description

@remittor

Test query:

GET /\xC0\xAF HTTP/1.1\r\n

Chain of Reasoning:

CVE-2000-0884 exploited exactly this pattern. Microsoft IIS on Windows decoded overlong UTF-8 sequences in URLs, allowing ..%c0%af.. to be interpreted as ../../.

4. **CVE-2000-0884 exploited exactly this pattern.** Microsoft IIS on Windows decoded overlong UTF-8 sequences in URLs, allowing `..%c0%af..` to be interpreted as `../../`. This enabled remote directory traversal, giving attackers access to files outside the web root. RFC 3629 Section 10 explicitly references this class of attack, noting "a widespread virus attacking Web servers in 2001" exploited overlong UTF-8 mishandling.

This CVE-2000-0884 refers to a completely different type of request: GET /%C0%AF HTTP/1.1\r\n

Activity

  1. remittor commented on Apr 4, 2026

    @remittor
    ContributorAuthor

    For requests of type GET /%C0%AF HTTP/1.1\r\n, we need to do a separate test.
    And I don't know what the HTTP/1.1 standard even says about encoding slashes with %2F and %C0%AF

  2. MDA2AV commented on Apr 5, 2026

    @MDA2AV
    Owner

    For requests of type GET /%C0%AF HTTP/1.1\r\n, we need to do a separate test. And I don't know what the HTTP/1.1 standard even says about encoding slashes with %2F and %C0%AF

    Yes, a separate test for this

  3. remittor commented on Apr 6, 2026

    @remittor
    ContributorAuthor

    And I don't know what the HTTP/1.1 standard even says about encoding slashes with %2F

    I decided not to decode "%2F" sequence:
    remittor/fastpysgi@c4b2263

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions