FSO exploit

From: Savas (Savas_at_discussions.microsoft.com)
Date: 04/20/05


Date: Wed, 20 Apr 2005 00:26:02 -0700

Hi,

My server was hacked over this weekend using the FSO exploit. It is sad that
by uploading one simple asp file to one website in a server, hacker can
access the whole machine, both drive C and drive D. Well I should have played
around with the IUSR permissions not allowing it to access drive C where web
files are not kept; however most sites hosted on my server require both read
and write access, giving the hacker the privilage to do anything he/she wants.

I thought of unregistering the FSO component but many sites use the
Dictionary object wich woul dalso be disabled. I am really stuck and cannot
find a solution.

Has anyone come up with a solution? I have limited hackers access to many
areas by disabling IUSR access; however many folders still need IUSR to write
to them. Also this asp file can see inside access databases too; which is
frightening.



Relevant Pages

  • Re: Writing to a printer from a WSH script called by ASP
    ... "Schadrach" wrote in message ... I mapped lpt1 on the server to the printer share on the workstation ... my .asp file in it. ...
    (microsoft.public.scripting.wsh)
  • Re: How do you modify and save txt or xml file using FP VBA or via
    ... Now I understand and know what you meant, and I do know capabilities of FSO ... I do not think I can execute asp code from this environment. ... I am trying to figure out how to use FP Server Extensions to help me EDIT ... > security update, then there is usually no charge for the call. ...
    (microsoft.public.frontpage.addins)
  • Re: wsx to asp ad rotator doesnt work
    ... if your ASP file presents a WSX ... may try to download the WMV from web server. ... instead of HTTPD create a local WSX that points to ...
    (microsoft.public.windowsmedia.server)
  • Re: file system management
    ... Except the word "fso" doesn't belong to asp.net dictionary. ... the server part is doable. ... Present it to the client allow drag and drop then post back to ... >> Mike, ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: Parse ASP file from ASP Page
    ... > web server When I post a data from this server ... >>> I have one ASP file in one WebServer which has to ... >>> parse the another ASP file in another webserver ... >>> If username and password is valid allow to login. ...
    (microsoft.public.frontpage.client)