[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Big IIS doodoo




--Damacus-- wrote:
> 
> One of my friends from NZ is friends with a group eeye.com.  He hangs around
> in mulysa and #beavuh on IRC.  Gotta love 'em.
> 
> Anyhow, they've discovered quite a hole in IIS which is quite nasty.
> 
> They gave MS a chance to write and reply before releasing this:
> 
> www.eeye.com
> http://www.eeye.com/database/advisories/ad06081999/ad06081999.html
> 
> Full exploit ASM source is available.  My friend says that there will be a
> Linux port of the exploit source, not that we have a use for that.
> 

I just did a little research comparing this to the recent ICMP
denial-of-service attack, put up on <A
HREF=http://slashdot.org/comments.pl?sid=99/06/15/2057242&threshold=0&commentsort=0&mode=thread&pid=3#134>Slashdot</A>. 
What makes it even more interesting is that MS themselves claim to have
discovered it on May 28, so 18 days and counting for a real fix (for
those sites that rely on the use of .HTR files, whatever they are).

John

--
To unsubscribe, send email to majordomo@luci.org with
"unsubscribe luci-discuss" in the body.