Re: IIS 6 strange file - site hacked



"Stefan Kanthak" <postmaster@[127.0.0.1]> wrote in message
news:%23h$nEXfpHHA.4364@xxxxxxxxxxxxxxxxxxxxxxx
"Roger Abell [MVP]" <mvpNoSpam@xxxxxxx> wrote:

To my awareness there are no known "holes" in IIS6, in fact
there have not been any security patches for IIS (6 or 5) since
the IIS 5 rollup was released years ago.

What about MSKB 328832?

Stefan


I take it that you disagree with the assessment in that KB stating
that the behavior is by design ? While it does describe an odd
behavior for webhits.dll, I would also note that it says this is an
issue with index server (apparently how it adjusts IIS behavior).

There have been a number of security related, critical isses with
codes that applicatively layer on the IIS frame, but as far as I have
seen none for the IIS frame since the rollup for IIS 5 was issued.

Roger


.



Relevant Pages

  • Re: Humble God
    ... When IIS is run on the scale of hardware for which it is ... you've ignored the security patches. ... that require a reboot to fix on *any* networked system. ... Kirk Strauser ...
    (comp.unix.bsd.freebsd.misc)
  • Re: IIS 6 strange file - site hacked
    ... To my awareness there are no known "holes" in IIS6, ... there have not been any security patches for IIS since ... the IIS 5 rollup was released years ago. ... Some of my friend told me that it is a IIS6 security hole. ...
    (microsoft.public.security)
  • Re: Reinstalling IIS4
    ... >>>updates following the reinstall of the Option Pack with IIS. ... So I'll need to download all the security patches ahead of time? ... rollup package the best way to go for this? ... Uninstall/reinstall IIS ...
    (microsoft.public.inetserver.iis.security)
  • deploying IIS on the internet
    ... I am planning to deploy either Windows2000+SP4+IIS5 or Windows2003+IIS6 on ... the internet, ... I would like to know what are the security patches for IIS that I need to ...
    (microsoft.public.inetserver.iis.security)
  • Re: IIS 6 strange file - site hacked
    ... there have not been any security patches for IIS since ... the IIS 5 rollup was released years ago. ... What about MSKB 328832? ...
    (microsoft.public.security)

Loading