RE: Microsoft Can't Win.

From: Adam Shephard (adam.shephard@firstfederalbanking.com)
Date: 10/09/01


Message-ID: <315154A4F911D2118D9E00805FA9C2C62A6B2B@nt0016a03>
From: Adam Shephard <adam.shephard@firstfederalbanking.com>
To: 'H C' <keydet89@yahoo.com>
Subject: RE: Microsoft Can't Win.
Date: Tue, 9 Oct 2001 14:59:14 -0500 


>if admins had disabled the ida/idq script mappings in
>IIS, they wouldn't have been vulnerable to Code Red,
>regardless of whether they had the patch installed or not.

Well, but wait a second. Had the script mappings not been enabled in the
first place, the admins wouldn't be faced with the task of having to disable
them. This speaks to the entire way MS does business.

Security should be the base. Ultra-security should be the goal. MS always
starts you out from a base of insecurity and then tells YOU how to fix
problems one at a time, once somebody raises a stink about the problems.

Now they're going to tell you, "Hey, don't worry about firewalling. We're
going to build a firewall right into your OS." This from the same people who
enabled ida/idq script mappings in IIS.



Relevant Pages

  • Re: Handling Authentication for all elements on a website
    ... through script mappings. ... Perhaps you could give them a script or program to run on the server ... >who refuse to allow me to map items so that asp.net handles authentication ... >access to the server and assigning all files to be handled by IIS? ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: IIS 6.0 Migration tool
    ... IIS Export. ... I noticed that is also screwed up my script mappings when I ... I did actually have a decent guess at replacing the path. ... Sean. ...
    (microsoft.public.inetserver.iis)
  • Re: Getting Started in ASP.Net
    ... Right click on the item in IIS for your site (either Default Website or the ... On the Documents tab, check to see if "Default.aspx" is listed. ... with .net 2.0 installation) then you should be ok I believe, ... ..net 1.1 you may need to check the script mappings to confirm. ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: Global.asax : BeginRequest Event
    ... you can do this by forcing the request through the ASP.NET runtime. ... You'll have to edit the script mappings in IIS for the application, ...
    (microsoft.public.dotnet.framework.aspnet)