Program and Source for Removal of IDA/IDQ Script Mappings (in response to Red Code Worm)

From: Critical Watch Bugtraqqer (bugtraq@criticalwatch.com)
Date: 07/20/01


Message-ID: <001901c1115b$8b62ab00$0bcfdf0a@theharem.net>
From: "Critical Watch Bugtraqqer" <bugtraq@criticalwatch.com>
To: <BUGTRAQ@SECURITYFOCUS.COM>
Subject: Program and Source for Removal of IDA/IDQ Script Mappings (in response to Red Code Worm)
Date: Fri, 20 Jul 2001 15:35:39 -0500

Hello everyone

This is in response to the sheer numbers of web server that got pummeled by
this new worm. While many people and firms created
exploit/checks/Advisories for this Dangerous exploit, we have yet to see a
"helping hand" program...until now! Having previously worked at a site
with a huge server farm I experienced how painful it can be to go to 175
machines to install a single hot fix. This program will allow you to sit at
your desk and simply yank the script mappings from the web server altogether
and eliminate some 6 or so vulnerabilities that are associated with Index
Services.

This is a very simple program that you can use to remove the .IDA and .IDQ
script mappings from the root of a web server and from all its sub-web
sites. We have included the source code as well as the setup packages. (the
metautil.dll has to get installed) for your perusal.

You may retrieve the 1.43 meg download from our web site at
http://www.criticalwatch.com/downloads/IDA_ScriptRemoval_Util.zip

Nelson Bunker, CISSP
V.P. of Security
Critical Watch



Relevant Pages

  • Re: How to judge whether content type is truly "text/html"?
    ... the web server and/or the developer who created the web site. ... HTTP response header. ... It shows that the response header has "ContentType: ...
    (microsoft.public.dotnet.languages.csharp)
  • Re: Newbie question about a web server
    ... I have just started to dabble in writing my own web server. ... When responding to the POST data received, it sends a 301 response, no ... "You don't have to know much about the HTTP ... Yes HTTP response code 200 does indicate a normal response. ...
    (comp.lang.python)
  • Re: InternetOpenUrl and local cache (2)
    ... The response MUST include the following header fields: ... If the conditional GET used a strong cache validator, ... the response SHOULD NOT include other entity-headers. ... In the web server, the file is defined to expire after 2 days. ...
    (microsoft.public.win32.programmer.networks)
  • Newbie question about a web server
    ... I have just started to dabble in writing my own web server. ... When responding to the POST data received, it sends a 301 response, no ... Except some basic that when the client request ... Some basic responce codes like 200 is OK for GET, ...
    (comp.lang.python)
  • Re: Odd problem
    ... Great response - thanks Jim! ... Jim Buyens wrote: ... > A lot of weird stuff happens to a Web server. ... > by FrontPage) is much more common. ...
    (microsoft.public.frontpage.client)

Quantcast