Re: What is PROPFIND & OPTIONS?

From: BB (Bernard_at_3exp.com)
Date: 02/27/03


From: "BB" <Bernard_at_3exp.com>
Date: Thu, 27 Feb 2003 17:25:19 +0800


>From the log, 501 - not implemented.
and options is 200 - successful

check who is using Microsoft-WebDAV-MiniRedir/5.1.2600
at 10.10.17.64 your Lan's machine.

if you server is patch uptodate, it should be fine. but there's
other possible channel too. not only webdav, which in your case
you don't have it at all.

Refer this to secure your box
http://support.microsoft.com/?id=282060

get urlscan. to filter unwanted http verbs.

Rgds.

"Fool" <fool@tom.com> wrote in message
news:uHqLBDk3CHA.2472@TK2MSFTNGP11.phx.gbl...
> As my server is NT 4, I guess that WebDav is not available in my server.
>
> If WebDav is not available and my server is up to date, is it possible for
a
> hacker to break in my server though WebDav?
>
>
>
>



Relevant Pages

  • [NT] Vulnerability in WebDAV XML Message Handler DoS (MS04-030)
    ... Get your security news from a reliable source. ... send a specially crafted WebDAV request to a server that is running IIS ... Mitigating Factors for WebDAV Vulnerability ...
    (Securiteam)
  • Re: WebDAV disabled!
    ... but the Web Service Extension named WebDAV is nothing to do with OWA - ... that extension enables WebDAV on the entire server, ... Look at the properties of the Microsoft Exchange Server ...
    (microsoft.public.exchange.admin)
  • Re: URLScan Logs
    ... I'm not a webdav expert, ... > Front Page server extensions are not configured for the> site. ... I have been experimenting with locking down this> IIS server and have the latest patches on it and have> followed many of the procedures outlined in several guides> including "From Blueprint to Fortress: A Guide to> Securing IIS 5.0". ... > contains disallowed header 'translate:' Request will be> rejected. ...
    (microsoft.public.inetserver.iis.security)
  • RE: Webdav Authentication
    ... credentials with your app server. ... I'm curious what you would be trying to do with WebDAV where you WOULDN'T ... | We have an application that communicates with Exchange via webdav. ... | having to store the credentials on our appserver. ...
    (microsoft.public.exchange.development)
  • Re: WebDAV disabled!
    ... I think you'll find that WebDAV is Prohibited by default. ... WebDAV service extension is enabled in Exchange Server 2003, ... The Extension named Microsoft Exchange Server is the one that enables ...
    (microsoft.public.exchange.admin)