Microsoft Briefs BetaNews on IIS Bug

By David Worthington | Published May 1, 2001, 11:56 PM

In light of the IIS 5 ISAPI Extension bug, a Microsoft spokesperson contacted BetaNews with a detailed briefing of the company's response. The flaw, which affects only customers running IIS5, is considered to be a serious threat since the software's default configuration leaves users open to attack. Microsoft has utilized many avenues to inform customers of the importance of applying the security patch. The release of the second Service Pack for Windows 2000 has also been delayed in order to incorporate this latest fix.

By sending a unique string of characters to an IIS 5 machine with Internet Printing enabled, a malicious user can gain full access to a Web server. The printing service module is installed by default. Microsoft informed BetaNews, "IIS 5.0 customers are not at risk if they have removed the Internet Printing capability from their servers. The IIS 5.0 security checklist recommends that this be done, and the security template provided in the checklist removes it. Likewise, the IIS 5.0 Lockdown Tool removes the capability unless the user explicitly chooses to retain it."

Comments

View comments by with a score of at least

although the MS site says the patch is for servers only, I installed it on my win2k pro without any problem. not sure if the bug affects win2k pro or not, but hey, I'm running IIS5...

Score: 0

|

Yea I saw the same thing. But I'm pretty sure the patch is in Windows Update even on Pro machines. Better install to be safe.

Score: 0

|

does anyone know if it effects people running Service Pack 2?

I got it installed and im running IIS 5 and it tells me it cant apply the patch cuz im running SP2.

any help appreciated.

Score: 0

|

Because SP2 has not been finalized, Microsoft pushed back the release to add this fix in. So yes, if you are running a beta copy of SP2, you will need to uninstall and download the final version upon release or apply the patch.

- Nate

Score: 0

|

Where can I find some proof of concept code for this?

Score: 0

|

EC's Kroes to US senators: Mind your own business on Oracle + Sun

If the AP is accurate, the EU's antitrust chief just told the United States Senate that any merger that takes place in the world is more her affair than theirs.

What does AT&T's 'Mark the Spot' app say about service quality?

That's a question for Betanews readers to answer in comments to this post.

Windows fix for TLS security bug still forthcoming, won't be Tuesday

Anyone looking for a fix for last month's discovery of a potentially serious security hole in TLS and SSL may have to wait until everyone is ready to act together.

Google rolls out real-time search, Near Me Now, extended personalization

Over time, searches from PCs and mobile phones will grow even "more personalized." But what about user privacy and search results that give you "the truth"?

Betanews Podcast: Rupert Murdoch and the buying stuff online problem

We'll have a more difficult time paying for online news if the underlying protocol for online payment has a big gaping hole in it.

Not the first, not the last, technology predictions for 2010

Carmi Levy | Wide Angle Zoom: The real truth is probably that what went around in 2009, will come around to haunt us next year.

Google Goggles: Hands on with the Shazam of the Real World

Google today unveiled Goggles, its visual search lab for Android devices that identifies objects by sight.

Microsoft: Windows 7 Family Pack wasn't 'pulled,' it just sold out

If you hurry, you may still be able to find the last Family Pack upgrade editions hanging around retail store shelves, but probably not so much online.

Clever iPhone game returns after being bumped over a name dispute

The game's simple concept and multitude of platforms and puzzles manage to pull off a retro, 8-bit style that's reminiscent of an old Atari game given a modern makeover.

Intel's marriage of CPU and GPU not ready for prime time

Although there will be an Intel component this month that can compute and plot in parallel, Betanews was told today, it won't be based on Project "Larrabee."

An alternative to Research in Motion's enterprise e-mail? There's an app for that

Good Technology today released an iPhone app compatible with its enterprise e-mail solution.