Toon posts:

[win2k]Nieuwe critical vuln. in IIS 5

Pagina: 1
Acties:

Verwijderd

Topicstarter
link : http://www.microsoft.com/...ity/bulletin/MS03-007.asp

-----BEGIN PGP SIGNED MESSAGE-----

CERT Advisory CA-2003-09 Buffer Overflow in Microsoft IIS 5.0

Original issue date: March 17, 2003
Last revised: --
Source: CERT/CC

A complete revision history is at the end of this file.

Systems Affected

* Systems running Microsoft Windows 2000 with IIS 5.0 enabled

Overview

A buffer overflow vulnerability exists in Microsoft IIS 5.0 running on
Microsoft Windows 2000. IIS 5.0 is installed and running by default on
Microsoft Windows 2000 systems. This vulnerability may allow a remote
attacker to run arbitrary code on the victim machine.

An exploit is publicly available for this vulnerability, which
increases the urgency that system administrators apply a patch.

I. Description

IIS 5.0 includes support for WebDAV, which allows users to manipulate
files stored on a web server (RFC2518). A buffer overflow
vulnerability exists in ntdll.dll (a portion of code utilized by the
IIS WebDAV component). By sending a specially crafted request to an
IIS 5.0 server, an attacker may be able to execute arbitrary code in
the Local System security context, essentially giving the attacker
compete control of the system.

Microsoft has issued the following bulletin regarding this
vulnerability:

http://www.microsoft.com/...ault.asp?url=/technet/sec urity/bulletin/ms03-007.asp

This vulnerability has been assigned the identifier CAN-2003-0109 by
the Common Vulnerabilities and Exposures (CVE) group:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0109

II. Impact

Any attacker who can reach a vulnerable web server can gain complete
control of the system and execute arbitrary code in the Local System
security context. Note that this may be significantly more serious
than a simple "web defacement."

III. Solution

Apply a patch from your vendor

A patch is available from Microsoft at

http://microsoft.com/down...9D32AC929B&displaylang=en

Disable vulnerable service

Until a patch can be applied, you may wish to disable IIS. To
determine if IIS is running, Microsoft recommends the following:

Go to Start | Settings | Control Panel | Administrative Tools | Services.

If the World Wide Web Publishing service is listed then IIS
is installed

To disable IIS, run the IIS lockdown tool. This tool is available
here:

http://www.microsoft.com/...lease.asp?ReleaseID=43955

......

and so on :)

  • FirmPete
  • Registratie: Juli 2001
  • Niet online
Ja, dus?

Een beetje (wos)-tweakerd krijgt die toch óók in z'n mail?

Firmpete on Aerie Peak


Verwijderd

Topicstarter
FirmPete schreef op 18 March 2003 @ 00:35:
Ja, dus?

Een beetje (wos)-tweakerd krijgt die toch óók in z'n mail?
Mijn ervaring leert dat een hele boel mensen niet geabonneerd zijn op dergelijke mailinglijsten... daarom dat ik het post.

Verwijderd

Topicstarter
Of via Cert:

http://www.cert.org/contact_cert/certmaillist.html

Cert was sneller binnen dan die van MS..... die van MS is trouwens hier nog niet eens binnen... ze hebben zeker problemen met de servers bij MS ;-)

(die draaien bijna allemaal al lekker Windows 2003 .net server dus zijn niet vatbaar)

Verwijderd

ik ben zowieso niet vatbaar... webdav al lang geleden uitgezet...

  • DiedX
  • Registratie: December 2000
  • Laatst online: 22:47
Hoe heb je dat geflikt? Ik heb eens gegoogled, en kwam op http://groups.google.com/...cf%40tkmsftngxa04&rnum=13 uit.

Er staat bij dat er alleen problemen gemeld zijn.

DiedX supports the Roland™, Sound Blaster™ and Ad Lib™ sound cards


Verwijderd

lees ms03-007 dan eens... daar staat het gewoon in... je moet dus srp1 (voor win2k sp2) gedraaid hebben...

edit: in een goede bui vandaag...

http://support.microsoft....aspx?scid=kb;en-us;241520

[ Voor 52% gewijzigd door Verwijderd op 27-03-2003 14:41 ]


  • DiedX
  • Registratie: December 2000
  • Laatst online: 22:47
Brr, bedankt! Een ander antwoord van Microsoft was op IIS maar uit te schakelen :)

Right!

DiedX supports the Roland™, Sound Blaster™ and Ad Lib™ sound cards

Pagina: 1