logo

NORAD Was Blind During Y2k Vigil -- Satellite Redundancy Wasn´t There


Latest News Stories:

cover-eletronicprivacy

Only $31.95

New Methodology:

shun

Product Reviews

OSAll is starting to do weekly product reviews, to be published every single Friday.  Check out software, book and hardware reviews.

 Check it out!

Front | Methods | BBS | FAQ | Adverts | Mail | Write | Link | Shop

"Y2k, all hype, all the time."

Microsoft Internet Information Server

Staff

On July 14, eEye

Microsoft Internet Information Server

Staff

On July 14, eEye released an advisory

Microsoft Internet Information Server

Staff

On July 14, eEye

Microsoft Internet Information Server

Staff

On July 14, eEye released an advisory and exploit for Microsoft Internet Information Server.  eEye, which is a company developing a security auditing tool similar to ISS´ core product, released the exploit to the public through the computer security mailing list Bugtraq.

The exploit affects 90% of the Windows NT Web servers on the Internet today, or approximately 1 million machines.

The exploit was basically a buffer overflow.  On the completion of the buffer overflow, a trojan would be uploaded to the IIS server, allowing a hacker or cracker to run any code on the server.

OSAll spoke with the author of the exploit,  who said the coding of the exploit was " not too difficult."  He went on to say " anyone with a running knowledge of assembler and with a little background on buffer overflows can accomplish the feat."

Microsoft moved relatively quickly to issue an advisory of their own about the situation, including a simple workaround.  They said a patch was in the works.  eEye, however, released a patch before Microsoft.

Interestingly, no Web site defacements have been reported using the IIS exploit.  Some, however, have predicted that this is the calm before the storm. 

OSAll has an article about Microsoft Security, closely related to this topic, which was written the same day eEye issued its advisory.

Don´t forget to discuss this issue on the OSAll BBSystem!

All content copyright 1998 - 99 unless book covers or otherwise noted.  Book covers copyright 1998 - 99 Amazon.com.  All OSAll-owned content may be reprinted with the following header added: "Copyright 1998 - 99 Owl Services.  Visit aviary-mag.com for computer security news and information."  Article authors retain a non-exclusive right to republish their work.   324