March 18, 2003
Buffer overflow in IIS WebDAV: Patch it now!

Microsoft has MS03-007 out. The bulletin describes a buffer overflow vulnerability in the WebDAV component of IIS 5.0 on W2K; Windows 2003 and Windows XP aren't affected. The practical effect of this vuln is that an attacker can run code of her choice on your server (at which point it's not really your server anymore.) The worst part is that an exploit for this problem is already circulating.

There are several ways to avoid this problem:

What about long-term solutions? Well, you should definitely be using IIS Lockdown on all your Windows 2000 servers. If you combine that tool with reasonable attention to patches, you will be in relatively good shape. You should aggressively follow up with MBSA scans to check for correct patch installation. In almost all cases, your life will be easier if you deploy the Software Update Service (SUS) to pull patches and stage them for mass installation. When I get a free minute, I'll be writing an article here describing exactly how to use SUS.

In the meantime, if you read and follow the recommendations in chapters 6 and 14 of the book, you can relax.

Posted by Paul at March 18, 2003 08:32 AM
Trackback Pings

TrackBack URL for this entry:
http://www.robichaux.net/cgi-bin/mt-tb.cgi/917

Comments

Post a comment




Remember Me?

(you may use HTML tags for style)

<
All of our program can supply you answers to math problems. . Garcinia Cambogia Extract . web design brisbane