Site Directory
Popular Links
|
Microsoft IIS Security HoleUsers urged to install patchITinfo SponsorERROR: Random File UnopenableThe file was not found on your file system. This means that it has either not been created or the path you have specified in $trrandom_file is incorrect.
Microsoft Reports Serious IIS Vulnerabilityby Dave MurphyISSN 1535-3613
As part of its installation process, IIS installs several ISAPI extensions -- .dlls that provide extended functionality. Among these is idq.dll, which is a component of Index Server (known in Windows 2000 as Indexing Service) and provides support for administrative scripts (.ida files) and Internet Data Queries (.idq files). A security vulnerability results because idq.dll contains an unchecked buffer in a section of code that handles input URLs. An attacker who could establish a web session with a server on which idq.dll is installed could conduct a buffer overrun attack and execute code on the web server. Idq.dll runs in the System context, so exploiting the vulnerability would give the attacker complete control of the server and allow him to take any desired action on it. Customers who cannot install the patch can protect their systems by removing the script mappings for .idq and .ida files via the Internet Services Manager in IIS. However, as discussed in detail in the FAQ, it is possible for these mappings to be automatically reinstated if additional system components are added or removed. Because of this, Microsoft recommends that all customers using IIS install the patch, even if the script mappings have been removed.
Dave's OpinionThis is a buffer overrun vulnerability. An attacker can use this vulnerability to gain complete control over a Microsoft web server. Once control is gained, the attacker could take any action on the server, including changing webpages, reformatting the hard drive or adding new users to the local administrators group.If you're running MS IIS, install the patch immediately. Also, tell your clients about this security hole and help them install the patch, too.
Call for CommentsWhat do you think? Leave your comments on the message center.
ReferencesMicrosoft's Security InformationMessage Center
Previous issues are on our website at http://itrain.org/itinfo/.
International Association of Information Technology Trainers
410.567.5366 Copyright © 2001 International Association of Information Technology Trainers, Ltd., All Rights Reserved
http://itrain.org/itinfo/2001/it010619.html |