<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>HTTP response split attacks, HttpWebRequest and the NET Framework 1.1 SP1</title><link>http://blogs.msdn.com/gzunino/archive/2004/09/05/225881.aspx</link><description>The .NET Framework 1.1 SP1 shipped recently and was pushed to Windows Update so you probably were already offered to download it. There is a package for Windows XP and or Windows Server 2003. This release contains several fixes but also attempts to enhance</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Miglioramenti alla sicurezza di .NET</title><link>http://blogs.msdn.com/gzunino/archive/2004/09/05/225881.aspx#225897</link><pubDate>Sun, 05 Sep 2004 23:12:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:225897</guid><dc:creator>Di .NET e di altre amenit</dc:creator><description /></item><item><title>Miglioramenti alla sicurezza di .NET</title><link>http://blogs.msdn.com/gzunino/archive/2004/09/05/225881.aspx#225898</link><pubDate>Sun, 05 Sep 2004 23:12:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:225898</guid><dc:creator>Di .NET e di altre amenit</dc:creator><description /></item><item><title>Fw 1.1 Sp1: pi</title><link>http://blogs.msdn.com/gzunino/archive/2004/09/05/225881.aspx#226040</link><pubDate>Mon, 06 Sep 2004 16:34:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:226040</guid><dc:creator>Alessandro Scardova</dc:creator><description /></item><item><title>re: HTTP response split attacks, HttpWebRequest and the NET Framework 1.1 SP1</title><link>http://blogs.msdn.com/gzunino/archive/2004/09/05/225881.aspx#232279</link><pubDate>Tue, 21 Sep 2004 07:36:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:232279</guid><dc:creator>Aleks</dc:creator><description>hi,&lt;br&gt;&lt;br&gt;i think that my web site have this security problem on two pages (rss and a page that display a picture &lt;a target="_new" href="http://www.Dotnet-Project.com/showimage.aspx"&gt;http://www.Dotnet-Project.com/showimage.aspx&lt;/a&gt;).&lt;br&gt;&lt;br&gt;One use ContentType=&amp;quot;text/xml&amp;quot; and the other ContentType=&amp;quot;image/gif&amp;quot;&lt;br&gt;&lt;br&gt;I will try to night to change the web.config but how can i fix it in other way (the secure way ?)&lt;br&gt;&lt;br&gt;Thank you</description></item><item><title>re: HTTP response split attacks, HttpWebRequest and the NET Framework 1.1 SP1</title><link>http://blogs.msdn.com/gzunino/archive/2004/09/05/225881.aspx#232452</link><pubDate>Tue, 21 Sep 2004 17:05:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:232452</guid><dc:creator>Gilles</dc:creator><description>Aleks: By reading your post, it is not immediately obvious that your site has this problem. There does not seem to be any spaces in ContentType which would indicate that this header is not the issue, if there is any issue. Are you 100% sure that there is an issue with the headers?&lt;br&gt;&lt;br&gt;Headers can come from two location: first the web application running (i.e. showimage.aspx) and the HTTP request processor (IIS and/or ASP.NET).&lt;br&gt;&lt;br&gt;IIS does not return &amp;quot;wrong&amp;quot; headers by default. ASP.NET, to the best of my knowledge does not either but does not prevent a web application to return malformed header names. If you suspect such a problem, I would start by looking at the application. Be sure to look at all HTTP handlers that might be modifying the stream after the page has been rendered.&lt;br&gt;&lt;br&gt;To fix it, you would find the offending code (the one that returns the wring header), change it to be a &amp;quot;good&amp;quot; header and rebuild the code.</description></item><item><title>re: HTTP response split attacks, HttpWebRequest and the NET Framework 1.1 SP1</title><link>http://blogs.msdn.com/gzunino/archive/2004/09/05/225881.aspx#232552</link><pubDate>Tue, 21 Sep 2004 20:38:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:232552</guid><dc:creator>Aleks</dc:creator><description>Thx Gilles for your response.&lt;br&gt;I tried to change my web.config and you're right this is not my problem.&lt;br&gt;&lt;br&gt;I've just make a small winapp to see informations such as headers that my page return and i was very surprised :&lt;br&gt;&lt;br&gt;When i look to the headers return by my local testing server it is all right BUT when i try to the main server (&lt;a target="_new" href="http://www.dotnet-project.com/showimage.aspx"&gt;http://www.dotnet-project.com/showimage.aspx&lt;/a&gt;) the ContentType header is missing. &lt;br&gt;The two servers run the same code and have the same webpages.&lt;br&gt;&lt;br&gt;Is it a security fix ?&lt;br&gt;Have an idea ?&lt;br&gt;&lt;br&gt;Thx for your help</description></item><item><title>RANT: Why does Microsoft keep adding breaking changes to the framework!</title><link>http://blogs.msdn.com/gzunino/archive/2004/09/05/225881.aspx#235740</link><pubDate>Wed, 29 Sep 2004 18:59:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:235740</guid><dc:creator>Scott Galloway's Personal Blog</dc:creator><description /></item><item><title>BizTalk Not able to send 50kb over http send port</title><link>http://blogs.msdn.com/gzunino/archive/2004/09/05/225881.aspx#236226</link><pubDate>Thu, 30 Sep 2004 17:26:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:236226</guid><dc:creator>Ramkumar</dc:creator><description>Hi Gilles&lt;br&gt;We are having issue with biztalk not able to send over 50 kb of xml  over http protocol thru biztalk.I couldnt find any article abt this issue.I would really appreciate if u can throw light on this subject&lt;br&gt;Thanks&lt;br&gt;Ramkumar</description></item><item><title>re: HTTP response split attacks, HttpWebRequest and the NET Framework 1.1 SP1</title><link>http://blogs.msdn.com/gzunino/archive/2004/09/05/225881.aspx#236265</link><pubDate>Thu, 30 Sep 2004 18:32:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:236265</guid><dc:creator>Gilles</dc:creator><description>Ramkumar: Biztalk 2004 uses POST to send data so it should be able to send more than 50Kb. This is most likely a configuration issue on the Web Application and/or BizTalk. You do not explain what happens exactly when you try to send more than 5oKb: any error, special behavior ... so it is impossible for me to figure out what is wrong in your specific case without looking at your system(s).&lt;br&gt;&lt;br&gt;Take a look at the web server logs and see if there is anything wrong there. Look for connections close, unusal status ... Take a look at the BizTalk machine's event log and see if there is anything wrong there as well.&lt;br&gt;&lt;br&gt;A few things to check:&lt;br&gt;&lt;br&gt;1) any proxy server in between that would limit the amount of a POST request?&lt;br&gt;2) you are sending the data in the body, right?&lt;br&gt;3) use a network monitoring tool like netmon or tcpdump (or ethereal) to capture the whole faulty HTTP session. You will be able to figure out who (if any) closes the connection first, what is the status of the close, how much data went in... It is important to figure out if BizTalk closes the connection first of if the web application is closing first even though BizTalk has more data to send,&lt;br&gt;4) are you sure you are not timing out while transmitting?&lt;br&gt;5) write a small web application that just saves the content to a file and point BizTalk to it so you can control the server yourself.&lt;br&gt;6) are you sure you are actually sending the right data? Maybe your send pipeline (if any) does not produce the data you expect (i.e. it produces less data than expected for instance). The HTTP send adapter will send only what it receives.&lt;br&gt;&lt;br&gt;There are of course so much more things you would normally check but this is going to get you started.</description></item><item><title>re: HTTP response split attacks, HttpWebRequest and the NET Framework 1.1 SP1</title><link>http://blogs.msdn.com/gzunino/archive/2004/09/05/225881.aspx#236364</link><pubDate>Thu, 30 Sep 2004 22:06:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:236364</guid><dc:creator>Ramkumar</dc:creator><description>Gilles&lt;br&gt;Thank you so much for the information.We have tried all the methods what you have mentioned steps.It seems BizTalk sends chunk of data over 48 kb and they have hotfix from microsoft to install the fix&lt;br&gt;&lt;a target="_new" href="http://support.microsoft.com/default.aspx?scid=kb;%5bLN%5d;839663#appliesto"&gt;http://support.microsoft.com/default.aspx?scid=kb;%5bLN%5d;839663#appliesto&lt;/a&gt;&lt;br&gt;&lt;br&gt;Though after installing  the hot fix we are in the same state getting bad response from the http server 400.If you can throw more light on this area  we would really appreciate your help&lt;br&gt;Thanks&lt;br&gt;Ramkumar</description></item><item><title>re: HTTP response split attacks, HttpWebRequest and the NET Framework 1.1 SP1</title><link>http://blogs.msdn.com/gzunino/archive/2004/09/05/225881.aspx#237216</link><pubDate>Sun, 03 Oct 2004 16:55:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:237216</guid><dc:creator>Ramkumar</dc:creator><description>Gilles&lt;br&gt;W finally figured it out after making the changes in registry key mentioned in KB 839633&lt;br&gt;&lt;br&gt;Thanks&lt;br&gt;Ramkumar</description></item><item><title>re: HTTP response split attacks, HttpWebRequest and the NET Framework 1.1 SP1</title><link>http://blogs.msdn.com/gzunino/archive/2004/09/05/225881.aspx#237264</link><pubDate>Sun, 03 Oct 2004 19:55:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:237264</guid><dc:creator>Gilles</dc:creator><description>Ramkumar: I m glad you got it to work. So this was the chunk encoding that ws causing issues.</description></item><item><title>Sharpreader, WordPress, and .NET Framework 1.1 SP1</title><link>http://blogs.msdn.com/gzunino/archive/2004/09/05/225881.aspx#240362</link><pubDate>Sun, 10 Oct 2004 08:05:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:240362</guid><dc:creator>Kevin's Stuff</dc:creator><description>Apparently there's a minor disconnect between these three items and RSS2 feeds. You'll notice that the last time I recieved a feed from nf0's Life was on the 23rd of September. The last update from scriptygoddess was on the 24th....</description></item><item><title>The server committed an HTTP protocol violation</title><link>http://blogs.msdn.com/gzunino/archive/2004/09/05/225881.aspx#243000</link><pubDate>Fri, 15 Oct 2004 22:42:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:243000</guid><dc:creator>Communication WEB</dc:creator><description>The server committed an HTTP protocol violation</description></item><item><title>journeying geek &amp;raquo; Your WordPress feeds are broken!</title><link>http://blogs.msdn.com/gzunino/archive/2004/09/05/225881.aspx#243473</link><pubDate>Sun, 17 Oct 2004 05:40:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:243473</guid><dc:creator>TrackBack</dc:creator><description>journeying geek &amp;amp;raquo; Your WordPress feeds are broken!</description></item><item><title>re: Solving the BizTalk 2004, Web Services, and the </title><link>http://blogs.msdn.com/gzunino/archive/2004/09/05/225881.aspx#252866</link><pubDate>Fri, 05 Nov 2004 17:12:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:252866</guid><dc:creator>Dot Net Dunk</dc:creator><description /></item><item><title>dot net 1 1 install problems</title><link>http://blogs.msdn.com/gzunino/archive/2004/09/05/225881.aspx#8701621</link><pubDate>Mon, 07 Jul 2008 15:15:49 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8701621</guid><dc:creator>dot net 1 1 install problems</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://melany.infovideoclub.info/dotnet11installproblems.html"&gt;http://melany.infovideoclub.info/dotnet11installproblems.html&lt;/a&gt;&lt;/p&gt;
</description></item></channel></rss>