Re: IIS vulnerability (MS06-034)



I understood that issue to be exclusively limited to uploaded web content
that is then served with processing by the ASP isapi that in turn is caused
to throw the error allowing the code to escape from normal constraints
placed on the ASP isapi by IIS.
In that case, casual use of a site, such as OWA, that may use ASP but
that does not allow alteration of the ASP code would not be impacted.
However, patching is still advised as authoring might in the future become
possible, but that patching is perhaps not needed so urgently.

"AI" <AI@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:8AFC110F-FC4B-4107-953F-A534CBF2D19A@xxxxxxxxxxxxxxxx
Microsoft released security bulletin MS06-034, saying that there is a flaw
in
ASP that could allow remote code execution. It's not clear to me from
this
bulletin whether the exploit could only be used if the IIS server hosts a
web
site that allows the user to upload files that IIS will execute, or
whether
this can be done through web forms. For example, would an OWA server be
affected? Users can submit data through web forms, and they can upload
files
as attachments, but not for processing as a script.

This bulletin on the one hand describes a vulnerability that, if I
understand correctly, would be exposed only in very rare case, but the
tone
of the bulletin makes it sound like every IIS server is vulnerable and
needs
to be patched.


.



Relevant Pages

  • Re: Send and recive files
    ... > I've created a submit form where the user can select a file to upload. ... > When the user press the button for submit the selected file, how my asp ... > How can i send file to the client? ... - When I have to send file from server to client, ...
    (microsoft.public.inetserver.asp.general)
  • Re: Confirmation message instead of page
    ... Do you mean replace the whole upload page with ASP or something in the ... > Since you can use ASP, consider writing your own form handler in ASP, ... >> Jonathan Blitz ... >>> Can't be done using FrontPage extensions. ...
    (microsoft.public.frontpage.programming)
  • Re: Send and recive files
    ... Set objFSO = Server.CreateObject ... > I've created a submit form where the user can select a file to upload. ... > When the user press the button for submit the selected file, how my asp ... Normally the server ...
    (microsoft.public.inetserver.asp.general)
  • Re: Need some fresh ideas
    ... I have an upload form that allows a user to browse and select ... asp server script validates the input ... SQL Server to it ... * editFile updates the form data. ...
    (comp.lang.javascript)
  • Re: Is it possible to display part of confirmation page while form is processing?
    ... - or Google for "ASP progress bar" for several JavaScript or other ASP ... To find the best Newsgroup for FrontPage support see: ... Once the upload was complete, ...
    (microsoft.public.frontpage.programming)