Serious new flaw found in IIS 6.0
A new remotely-exploitable vulnerability has been found in the Microsoft IIS 6.0 Web server. The flaw is quite similar to one that was discovered eight years ago in earlier versions of IIS, and exploitation of the weakness could enable an attacker to upload content to the vulnerable server.
Editor's Pick
The vulnerability is in the implementation of the WebDAV protocol in IIS 6.0, which allows remote users to access and modify documents on a Web server. News of the vulnerability, discovered by a researcher named Nikolaos Rangos, hit the Full Disclosure security mailing list last week. Here are the details, from Rangos's advisory:
This vulnerability allows remote attackers to bypass access restrictions on vulnerable installations of Internet Information Server 6.0. The specific flaw exists within the WebDAV functionality of IIS 6.0. The Web Server fails to properly handle unicode tokens when parsing the URI and sending back data. Exploitation of this issue can
result in the following:
– Authentication bypass of password protected folders
– Listing, downloading and uploading of files into a password protected WebDAV folder
There is no patch available for this vulnerability, so experts at the SANS Internet Storm Center are recommending that people disable WebDAV in the interim. Thierry Zoller has a good analysis of the IIS 6.0 vulnerability as well.
Microsoft's Security Response Center is investigating the WebDAV vulnerability and is in the process of putting together an advisory on it.
"Microsoft is investigating new public claims of a possible vulnerability in Internet Information Services. We’re currently unaware of any attacks trying to use the claimed vulnerability or of customer impact. We are working on a security advisory to provide customers with guidance to help protect themselves," said Christopher Budd, security response communications lead at Microsoft.
Commenting on this Article is closed.
Today's Most Popular
Most Commented Stories
-
Forget 'Brogrammers,' Women Have The Edge In DEFCON Social Engineering Contest (10)
-
Defense Contractor Northrop Grumman Hiring For Offensive Cyber Ops (11)
-
The Internet Crime Complaint Center recently warned of malware targeting travelers connecting to Wi-Fi. When traveling, do you (1)
-
Facebook Cancellation Malware Disguised As Adobe Update Making Rounds (3)
-
HULK DDoS Tool Smash Web Server, Server Fall Down (4)
Newsletter Sign-up
Take Our Poll
Listen to Latest Podcasts
-
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.




