OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Security issue over IIS3 and IIS4 - Additional information
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Security issue over IIS3 and IIS4 - Additional information


  • To: NTBUGTRAQLISTSERV.NTBUGTRAQ.COM
  • Subject: Security issue over IIS3 and IIS4 - Additional information
  • From: Toby Beaumont <tobyWIRESTATION.CO.UK>
  • Date: Fri, 3 Jul 1998 17:18:58 +0100
  • Organization: Wirestation
  • Reply-To: Toby Beaumont <tobyWIRESTATION.CO.UK>
  • Sender: Windows NT BugTraq Mailing List <NTBUGTRAQLISTSERV.NTBUGTRAQ.COM>

Regarding the recent 'discovery' of the security hole in IIS3 and IIS4,
Microsoft have issued an explanation and hotfixes at

http://www.microsoft.com/security/bulletins/ms98-003.htm

However, their claim that only IIS3 and IIS4 are effected is not
entirely true.

Peer Web Services (PWS) (ie. for NT Workstation) is also affected and
the hotfixes provided by Microsoft for IIS3 or IIS4 should not be used
to fix PWS as it will trash it.

If anyone is aware of a fix for PWS, could you let me know?

--
==================
Toby Beaumont
Senior Web Developer
The Wirestation

Tel +44 (0)171 336 6510
http://www.wirestation.co.uk