BlackIce and Publishing with FrontPage

From: Adam Marx (AdamMarx_at_webajm.com)
Date: 08/05/03


Date: Mon, 4 Aug 2003 22:14:01 -0400


I have a client who is publishing thier site by means of FrontPage by simply
using the "Publishing" feature or via HTTP. I am currently running Windows
2000 server sp4 installed and BlackIce ver 3.6.cbr. Everytime my client
tries to publish they get blocked by the firewall and BlackIce posts the
reason as a ([Denial of Service] This signature detects an HTTP POST command
to the '/_vti_bin/shtml.dll/_vti_rpc' or the \/_vti_bin/_vti_aut/author.dll\
file. The POST includes a \method\ of more than 256 characters.) DoS.

I am currently runningBlackIce as"Trusting" and I need to figure out what to
do to allow my client to publish.

Does anyone have any ideas?

T.I.A.

AJM,



Relevant Pages

  • [UNIX] Alteon ACEdirector Signature/Security Bug
    ... A new security bug has been discovered in the Nortel Alteon ACEdirector ... HTTP clients could exploit it to determine the IP addresses of ostensibly ... "hidden" web servers that are load-balanced by the ACEdirector. ... uses it to persistently map a series of HTTP client requests to the same ...
    (Securiteam)
  • Alteon ACEdirector signature/security bug
    ... This is to inform you of a bug in the Nortel Alteon ACEdirector ... balance incoming HTTP requests made to one virtual IP address ... amongst the real IP addresses of multiple HTTP servers. ... series of HTTP client requests to the the same one of the real HTTP ...
    (Bugtraq)
  • Re: Encrypted or Not Encrypted
    ... Client software renders the form. ... to schema, it initiates ssl handshake. ... The agent acting as the HTTP client should also act as the TLS ...
    (Security-Basics)
  • Re: Firewall session disconnects after 2 minutes of inactivity
    ... I want to start by pointing out the following: HTTP keep-alives and anything ... involved in the early stage of the connection when the client downloads the ... The HOD server I mean. ... when the session takes place through the ISA Server? ...
    (microsoft.public.isa)
  • Re: Mcafee FTP Mirror Sites and ISA Server 2004 Authentication
    ... Client IP: ... Destination IP: ... Protocol: http ... Action: Failed Connection Attempt ...
    (microsoft.public.isa)

Loading