Re: Q313450 and Q319733 breaks Microsoft Site Server 3.0 membership authentication (additional information)

From: Tod Beardsley (todb@PLANB-SECURITY.NET)
Date: 04/12/02


Date:         Fri, 12 Apr 2002 10:01:55 -0500
From: Tod Beardsley <todb@PLANB-SECURITY.NET>
To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM

3APA3A (Thursday, April 11, 2002, 5:09 AM) wrote:

> After Q313450 installed Membership authentication via LDAP supported by
> Microsoft Site Server 3.0 doesn't work.

http://support.microsoft.com/default.aspx?scid=kb;en-us;Q317815

Q317815 appears to fix the Site Server 3.0 Personalization and
Membership authentication after installing Q319733. Short story: get a
new DLL for your Site Server.

Contrary to the article's recommendation, I have not seen a need to
boot in Safe Mode to apply the fix.

I cannot say if this work around reintroduces exposures. However,
since you're not replacing IIS-related files, you /should/ retain all
the protections that the fixes for MS02-018 give you.

YMMV.

--
Tod Beardsley, Security Analyst
"It's ok to yell fire in a crowded theater
if the theater is actually on fire."



Relevant Pages

  • RE: EVENT ID 4100 problem
    ... containing this fix. ... > the subscriber ... > CoCreateInstanceEx returned HRESULT ... on my site server I'm getting these error ...
    (microsoft.public.sms.admin)
  • RE: WMI Repository Rebuild on Site Server
    ... If you are hesitant to open up call, what are your "issues with HINV" on ... Maybe we can help you fix that without doing anything drastic, ... the server and restore from backup, because messing w/WMI on your site server ... Any problems rebuilding the repository on ...
    (microsoft.public.sms.admin)
  • Re: Advanced Client in mixed NT/AD Domain Help
    ... I am having the same problem, but it only started occuring after i ... To fix it, I moved it back to my site server, watched the ...
    (microsoft.public.sms.admin)
  • SMS security update (mssecure.cab)
    ... OK I think I know whats happening, however I am not sure how to fix this ... I look at the mssecure.cab file on the site server and it is the ... but on my clients machines within the vpcache folder it ...
    (microsoft.public.sms.admin)
  • SMS security update (mssecure.cab)
    ... OK I think I know whats happening, however I am not sure how to fix this ... I look at the mssecure.cab file on the site server and it is the ... but on my clients machines within the vpcache folder it ...
    (microsoft.public.sms.misc)