Re: Alert: New Code Red F worming its way through the 'net
From: Randy Hinders (randy@DONET.COM)
Date: 03/11/03
- Previous message: Russ: "Alert: New Code Red F worming its way through the 'net"
- Maybe in reply to: Russ: "Alert: New Code Red F worming its way through the 'net"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Tue, 11 Mar 2003 14:03:11 -0500 From: Randy Hinders <randy@DONET.COM> To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
Russ,
The best thing an IIS admin can do (other than patching their system) is
to remove the 'blank' host header. The default settings of IIS 4.0, 5.0
and 5.1 allow the server to answer to the IP of the local server. If
they remove the blank host header they are forcing the host header to
match something listed in IIS.
After the last Code Red I wrote an article that Brett Hill posted at
http://www.iisanswers.com/articles/hinders_rant.htm
Thanks for the heads up!
Randy A. Hinders
MCT (ret.), MCSE, MCP +I & A+
NT Systems Administrator
DONet, Inc
randy@donet.com
www.donet.com
~~Hoka Hey, Lakotas~~
oooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo
Delivery co-sponsored by TruSecure
oooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo
FREE 14-DAY TRIAL of New Threat & Vulnerability Notification Service
TruSecure's new IntelliShield(tm) web-based threat and vulnerability
service isn't your typical alert service. Supported by TruSecure's vast
intelligence resources - including the ICSA Labs - IntelliShield's early
warning, analysis, decision support, and threat management tools provide
organizations with unmatched intelligence to better protect critical
information assets. Experience it for yourself - just click below to begin
your FREE, NO OBLIGATION 14-day trial today!
http://www.trusecure.com/offer/s0074/
oooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo
- Previous message: Russ: "Alert: New Code Red F worming its way through the 'net"
- Maybe in reply to: Russ: "Alert: New Code Red F worming its way through the 'net"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|