Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Focus on Microsoft
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
RE: IIS 4 Security Dec 11 2002 06:53PM
Ogle Ron (Rennes) (ron ogle thomson net)
Your friend is smart. You don't need to have a username/password to do many
of the buffer overflows, directory traversal, and URL encoding attacks
against an unpatched IIS server. You didn't say but if the IIS server is
not protected by a firewall to only allow port 80 connections, then your
Windo...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus