Technology Industry
Industry: Email Alert RSS FeedAnother Security Hole In Microsoft Iis Web Server
Computergram International, July 6, 1998
Another problem with web server security has been identified and patched. Adding '::$DATA' to certain URLs hosted on Microsoft's Internet Information Server makes browsers download the source code to scripts. That source may contain userIDs and passwords. However, the vulnerability may not be as severe as some observers first feared, and Microsoft has been quick to issue a hot fix. This latest hole in IIS security was reported by Paul Ashton, a UK consultant and co-moderator of the NTBugTraq mailing list. "It is left as an exercise for the reader to think of further implications in other programs running on NT," Ashton concluded drily. Dave Winer, CEO of Userland Software and webmaster of Scripting.com, claims the flaw lets hackers into frequent flier mileage databases and credit card records. "If I operated a Windows-based web server with script code of any kind, I'd shut it down while I did a complete site audit," he writes. But Russ Cooper, co-moderator with Paul Ashton of NTBugTraq, isn't so sure. "Dave's giddy with information," he says. "What you can get access to is the username and password - maybe." That information could let hackers breach a database, assuming the sitemaster hadn't already restricted access to certain trusted machines. If that has been done, the hackers would still have to compromise those machines before they could get in. Cooper suggests that the more damaging consequence of the bug is the most obvious one. "All that hard work you did in coming up with your dream web application is now completely up for grabs," he says, "if any old person can get a look at your source." Cooper points out that webmasters running IIS can secure their sites immediately by disabling read access to all directories containing executable content. "Of course they'll then have to go back and enable read for files that are not executable, otherwise the gifs [image files] won't download," he warns. For a software patch, visit Microsoft at http://www.microsoft.com/security/bulletins/ms98-003.htm or Softwing at http://www.softwing.com/iisdev/ddatafix/.
>Most RecentTechnology Articles
- eBay Admits to Using Confidential Craigslist Info to Compete
- AT&T Decides to Commit Financial Suicide, Discourage iPhone Data Use...
- AOL Spinoff Faces Not Challenges, Not Hurdles, But Steep Cliffs
- Google, Apple, Microsoft, Other Tech Courting the Media
- Mid-Cap Board Directors Make More in Tech than in Other Industries
- More »
CXO UnpluggedSmart Business interviews on BNET
Brought to you by CBS MoneyWatch.com
- Best- and Worst-Paid College Degrees
- 6 Things You Should Never Do on Twitter or Facebook
- How Much Sleep Do You Really Need?
- 6 Big Myths about Gas Mileage
Most Recent Technology Articles
- INTERVIEW WITH BEN BUTTERS, DIRECTOR OF EUROPEAN AFFAIRS AT EUROCHAMBRES : "A PERFECT ROAD MAP FOR EU CLUSTERS DOES NOT EXIST".
- AGENDA.(Brief article)(Conference notes)
- FIGHT AGAINST INTERNET PIRACY.
- INTERNET : AUTHORS' SOCIETIES URGE ACTION AGAINST PIRACY.
- TELECOMMUNICATIONS : BUSINESSEUROPE HOSTILE TO FURTHER CONTRACTUAL OBLIGATIONS.(Brief article)
Most Recent Technology Publications
Most Popular Technology Articles
- BizRate to monitor in-store customer satisfaction for Office Depot stores - Market Intelligence
- Effects of creative, educational drama activities on developing oral skills in primary school children
- 3G: naughty or nice? PhoneErotica.com generates over 300 million hits per month, and rings up more minutes of use per month than MSN
- Failed businesses in Japan: a study of how different companies have failed, and tips on how to succeed, in the Japanese market
- Face recognition using eigenfaces and neural networks



