Re: Q313450 and Q319733 breaks Microsoft Site Server 3.0 membership authentication (additional information)

From: Tod Beardsley (todb@PLANB-SECURITY.NET)
Date: 04/12/02


Date:         Fri, 12 Apr 2002 10:01:55 -0500
From: Tod Beardsley <todb@PLANB-SECURITY.NET>
To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM

3APA3A (Thursday, April 11, 2002, 5:09 AM) wrote:

> After Q313450 installed Membership authentication via LDAP supported by
> Microsoft Site Server 3.0 doesn't work.

http://support.microsoft.com/default.aspx?scid=kb;en-us;Q317815

Q317815 appears to fix the Site Server 3.0 Personalization and
Membership authentication after installing Q319733. Short story: get a
new DLL for your Site Server.

Contrary to the article's recommendation, I have not seen a need to
boot in Safe Mode to apply the fix.

I cannot say if this work around reintroduces exposures. However,
since you're not replacing IIS-related files, you /should/ retain all
the protections that the fixes for MS02-018 give you.

YMMV.

--
Tod Beardsley, Security Analyst
"It's ok to yell fire in a crowded theater
if the theater is actually on fire."



Relevant Pages

  • RE: EVENT ID 4100 problem
    ... containing this fix. ... > the subscriber ... > CoCreateInstanceEx returned HRESULT ... on my site server I'm getting these error ...
    (microsoft.public.sms.admin)
  • Re: Advanced Client in mixed NT/AD Domain Help
    ... I am having the same problem, but it only started occuring after i ... To fix it, I moved it back to my site server, watched the ...
    (microsoft.public.sms.admin)
  • SMS security update (mssecure.cab)
    ... OK I think I know whats happening, however I am not sure how to fix this ... I look at the mssecure.cab file on the site server and it is the ... but on my clients machines within the vpcache folder it ...
    (microsoft.public.sms.misc)
  • SMS security update (mssecure.cab)
    ... OK I think I know whats happening, however I am not sure how to fix this ... I look at the mssecure.cab file on the site server and it is the ... but on my clients machines within the vpcache folder it ...
    (microsoft.public.sms.admin)