Re: CodeRed Observations. ##

From: Andrew Bates (abates@omeganetserv.com)
Date: 03/18/03

  • Next message: Robinson, Jonathon: "RE: SPM2000$ Rouge Share"
    From: "Andrew Bates" <abates@omeganetserv.com>
    To: "root" <root@ns1.transurban.com.au>, <incidents@securityfocus.com>
    Date: Tue, 18 Mar 2003 12:38:10 -0700
    
    

    > Heres the article that I read about IIS and IE interactions:
    > http://grotto11.com/blog/slash.html?+1039831658 . Besides quicker
    > propagation, not using a handshake would allow spoofed IPs so that it
    > would be harder to track down and fix.

    If you read through to the end of the article, the author points out that
    they discovered NT 4.0 IP stack was performing this, and that any client or
    server running on top of NT would behave in this manner. So it does not
    appear to be a "feature" of IE or IIS, but, rather, a feature of NT 4.0.

    These results were also presented in 1997, and the author suggests that the
    NT stack may have been changed since then.

    Andrew

    ----------------------------------------------------------------------------

    <Pre>Lose another weekend managing your IDS?
    Take back your personal time.
    15-day free trial of StillSecure Border Guard.</Pre>
    <A href="http://www.securityfocus.com/stillsecure"> http://www.securityfocus.com/stillsecure </A>


  • Next message: Robinson, Jonathon: "RE: SPM2000$ Rouge Share"

    Relevant Pages

    • Re: Should I develop on IIS6 or VS2005 web server?
      ... What feature of IIS 6 do you plan to administer in your ... > the development environment should match the server. ...
      (microsoft.public.dotnet.framework.aspnet)
    • Re: IIS 7 and Enabling ASP.Net Extensions...
      ... Application Features determine the capability of the IIS Web Server. ... ASP.Net Feature in order for IIS to be able ... then you MUST install the ASP.Net Feature for IIs to be able ... Asp.Net extensions were installed and enabled. ...
      (microsoft.public.inetserver.iis)
    • Re: server dimmed under Tool tab
      ... I'll take your word for how it works under Unix - on IIS you're at the mercy ... Mine allows the feature but I still wouldn't want to use ... > And also it depends upon the type of server. ... that feature is ONLY available if the host has ...
      (microsoft.public.frontpage.client)
    • Re: IIS 6.0 Anonymous Login:::Please help
      ... The feature "Allow IIS to control password" of the anonymous user requires ... Prior to IIS6, IIS ran as LocalSystem, so this feature just works. ... get the secure default values of WS03 clean install (on upgrade, ...
      (microsoft.public.inetserver.iis)
    • RE: IIS - Secure Site and Password Change
      ... You asked about changing passwords by using IIS. ... There can be numerous unexpected things occur with this feature and there ... are several articles on our support site. ... patch is not a cumulative patch. ...
      (microsoft.public.inetserver.iis.security)