BetaONE will rise again!


Reply
  #1  
Old 6th Jun 07, 05:44 PM
Alpine's Avatar
Alpine Alpine is offline
Retired Crew
 
Join Date: Feb 2002
Location: Run Forest, RUN!!
Posts: 3,601
Alpine is on a distinguished road
Send a message via ICQ to Alpine Send a message via AIM to Alpine
M$ tells hackers how to take apart its IIS
As if they needed a hand


MICROSOFT IS showing all comers how to hack into its Internet Information Server and is not giving any hints how to work around the problem.


The Vole says an exploit, which was discovered on December 15, 2006, and made public at the end of May, is actually a feature.
Apparently versions 5.x allow bypass of basic authentication by using the "hit highlight" feature. The hit-highlighting feature can be used by an unauthorised user to nick documents.

The Internet Storm Centre says that hackers have not used this exploit to take over systems to date, that could well change. Especially now we've told them about it.

The Vole has written up the problem in its Knowledge Base article 328832. Apparently, hit-highlighting with Webhits.dll only relies on the Microsoft Windows NT ACL (Access Control List) configuration on 5.x versions.
Security experts are a bit stunned at the Volish attitude. Rather than supply a patch or workaround, Microsoft published six steps to reproduce the exploit. In otherwords Vole is telling the world how to exploit products being used by their customers.

The official Volish line is that all users should upgrade to IIS (Internet Information Services) version 6.0 running on Microsoft Windows Server 2003. IIS 6.0 significantly increases Web infrastructure security, it says here.

And here.

The INQuirer
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Chinese hackers constantly attack the US Alpine BetaONE News 0 19th Feb 07 09:42 PM
Suspected hackers to be banned from web Alpine BetaONE News 0 19th Jul 06 01:09 PM
Chinese hackers breach US military defences Alpine BetaONE News 0 24th Nov 05 06:04 PM
IIS 7 Short Overview Video NewsBot NeoWin News 1 25th Sep 05 07:39 AM
Linux fights off hackers NewsBot NeoWin News 0 17th Jan 05 08:00 PM


All times are GMT +1. The time now is 03:10 PM.


Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.