OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Tod Beardsley (todbPLANB-SECURITY.NET)
Date: Fri Apr 12 2002 - 10:01:55 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    3APA3A (Thursday, April 11, 2002, 5:09 AM) wrote:

    > After Q313450 installed Membership authentication via LDAP supported by
    > Microsoft Site Server 3.0 doesn't work.

    http://support.microsoft.com/default.aspx?scid=kb;en-us;Q317815

    Q317815 appears to fix the Site Server 3.0 Personalization and
    Membership authentication after installing Q319733. Short story: get a
    new DLL for your Site Server.

    Contrary to the article's recommendation, I have not seen a need to
    boot in Safe Mode to apply the fix.

    I cannot say if this work around reintroduces exposures. However,
    since you're not replacing IIS-related files, you /should/ retain all
    the protections that the fixes for MS02-018 give you.

    YMMV.

    --
    Tod Beardsley, Security Analyst
    "It's ok to yell fire in a crowded theater
    if the theater is actually on fire."