RE: Microsoft Security Advisory MS 03-007

From: Kim Christiansen (kcn@carlbro.com)
Date: 03/18/03

  • Next message: Jonathan Grotegut: "RE: Microsoft Security Advisory MS 03-007 - Problems"
    From: Kim Christiansen <kcn@carlbro.com>
    To: Focus-MS <focus-ms@securityfocus.com>
    Date:  Tue, 18 Mar 2003 15:42:41 +0100
    
    

    > > Douglas,
    > > You say "IIS servers are actively being compromised already,
    > > before the bulletin was released" --- do you have any links to
    > > documentation about this? I haven't heard of this.
    > >
    > > Also, besides IIS, what methods are available to exploit the
    > > vulnerability in ntdll.dll ?"
    >
    > I must admit, I don't want to be scaremongerish. One
    > published article that
    > is low on details is at
    > http://www.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=22029
    >

    http://www.msnbc.com/news/886524.asp?0cv=CB10

    -Kim

    ----------------------------------------------------------------------
    ALERT: How a Hacker Uses SQL Injection to Steal Your SQL Data!
    It's as simple as placing additional SQL commands into a Web Form input
    box giving hackers complete access to all your backend systems!
    http://www.spidynamics.com/mktg/sqlinjection33


  • Next message: Jonathan Grotegut: "RE: Microsoft Security Advisory MS 03-007 - Problems"

    Relevant Pages

    • Remotely reading configuration info from an IIS 7.0 via c#
      ... Not sure which is the correct forum to post this (I have tried wmi ... I am trying to remotely connect to an IIS 7.0 server instance to read ... configuration parameters for documentation purposes. ... I am just trying to create a console app that will document the os, sql ...
      (microsoft.public.vsnet.general)
    • Re: PROBLEM: ASP on IIS 5 secured via "Windows Integrated Authentication" accessing "
      ... uses NT group based permissons on the SQL Server, ... > transfered to the IIS box and IIS does a local logon. ... > delegation for all accounts. ...
      (microsoft.public.inetserver.iis.security)
    • RE: Co-Hosting SQL with IIS FTP service
      ... there are no functional conflicts between SQL and IIS; their network resource demands are unique. ... If the machine resources are enough, you can also use your favorite virtualization technology to separate the FTP and SQL servers and thus avoid the combinational security issues that public FTP services may impose on the SQL server. ... Co-Hosting SQL with IIS FTP service ...
      (Focus-Microsoft)
    • ANNOUNCE - Muldis::DB v0.0.0 released, in p5+p6
      ... I am pleased to announce the release of Muldis::DB version 0.0.0 for Perl 5 on CPAN. ... If you want to read all the Muldis::DB documentation that exists now, I recommend doing so in this order: ... Muldis::DB implements a D language as defined by Hugh Darwen and Chris Date, and presents a superior interface for working with the relational model of data, contrasted with SQL. ...
      (perl.dbi.users)
    • RE: MS patch-scanner for Win-NT, 2K, IIS, SQL
      ... MS patch-scanner for Win-NT, 2K, IIS, SQL ... check the local computer - so there are no FW or Gateway problems. ... SQL Hi, I get the following error message when I try ...
      (Focus-Microsoft)

  • Quantcast