Q313450 and Q319733 breaks Microsoft Site Server 3.0 membership authentication (additional information)
From: 3APA3A (3APA3A@SECURITY.NNOV.RU)Date: 04/11/02
- Previous message: Attonbitus Deus: "Re: IIS4 ISSUES RE: Alert: Microsoft Security Bulletin - MS02-018"
- Next in thread: Tod Beardsley: "Re: Q313450 and Q319733 breaks Microsoft Site Server 3.0 membership authentication (additional information)"
- Reply: Tod Beardsley: "Re: Q313450 and Q319733 breaks Microsoft Site Server 3.0 membership authentication (additional information)"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Thu, 11 Apr 2002 14:09:10 +0400 From: 3APA3A <3APA3A@SECURITY.NNOV.RU> To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
Dear,
After Q313450 installed Membership authentication via LDAP supported by
Microsoft Site Server 3.0 doesn't work. While may not be a big problem
by itself it becomes very significant after latest holes discovered,
because Q319733 also contains Q313450 and thus can't be applied to site
running Microsoft Site Server 3.0.
Tested configuration:
Microsoft Windows 2000 Server SP2 + SRP1
Microsoft IIS 5.0
Microsoft Site Server 3.0 SP4 Commerce Edition
The problem is probably in infocomm.dll. Workaround may be:
1. Save a copy of infocomm.dll
2. Install Q319733 rollup fix
3. Restore original version of infocomm.dll
It makes working configuration but it's not clear if all Q319733 issues
are covered after this downgrade.
-- http://www.security.nnov.ru /\_/\ { , . } |\ +--oQQo->{ ^ }<-----+ \ | ZARAZA U 3APA3A } +-------------o66o--+ / |/ You know my name - look up my number (The Beatles)
- Previous message: Attonbitus Deus: "Re: IIS4 ISSUES RE: Alert: Microsoft Security Bulletin - MS02-018"
- Next in thread: Tod Beardsley: "Re: Q313450 and Q319733 breaks Microsoft Site Server 3.0 membership authentication (additional information)"
- Reply: Tod Beardsley: "Re: Q313450 and Q319733 breaks Microsoft Site Server 3.0 membership authentication (additional information)"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]