RE: XWT Foundation Advisory

From: Thor Larholm (thor@pivx.com)
Date: 07/30/02


From: "Thor Larholm" <thor@pivx.com>
To: "Microsoft Security Response Center" <secure@microsoft.com>, <bugtraq@securityfocus.com>
Date: Tue, 30 Jul 2002 11:50:40 +0200


> From: Microsoft Security Response Center [mailto:secure@microsoft.com]
<snip mitigating factors>

I for one am in agreement on this issue, especially with regards to
"Default" sites on e.g. IIS - it is very uncommon for anyone to serve
content from the "Default" site (without checking the Host header) these
days.

That's not to say that sites like support.microsoft.com does not do this as
it seems to operate on the "Default" site, neglecting the most important
mitigating factor.

I still quite fail to see the relevance to firewalls, as nothing is
circumvented - the administrator has explicitly allowed HTTP traffic on
(most often) port 80.

Out of plain curiosity, how is this fixed in IE6SP1 - as the Netscape team
fixed it by demanding both sites to set document.domain, regardless if one
is the parent?

Regards
Thor Larholm, Security Researcher
PivX Solutions, LLC

Are You Secure?
http://www.PivX.com



Relevant Pages

  • Re: Email constantly sending
    ... Did you get the email I sent as requested and the POP3 details? ... I haven't touched the IIS etc, ... Regards ... >> In the meantime I was looking to uninstall the ILS and SMTP. ...
    (microsoft.public.windows.server.sbs)
  • Re: FoxPro 6.0 and ODBC
    ... Remote access? ... > are the same version with regards to the System DSN i created, ... > believe it is an issue with IIS 5.1. ... user IIS especially ASP is running. ...
    (microsoft.public.data.odbc)
  • RE: Microsoft .NET, ASP.NET, and IIS - any opinions?
    ... Regards, ... >> We all know that IIS has it's flaws - and that for many of ... >> IIS server we have live right now), ...
    (Focus-Microsoft)
  • RE: MSExchangeSA Event 1031
    ... story there might be something with ASPNET account. ... Any changes in IIS ... Regards, ... Michel Boks - B.ICT ...
    (microsoft.public.exchange.admin)
  • Re: IIS Fails Intermittently
    ... Regards, ... Microsoft MVP [Windows] ... "Barry McConomy" wrote: ... | I have a Windows 2000 server with IIS to host about 50 WEB sites. ...
    (microsoft.public.win2000.general)