Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Security Holes That Run Deep
Mark Burnett, 2004-12-20

How a seemingly simply Microsoft bug betrayed its author's disdain for a wide range of secure coding principles.

Submit Comment Mode:
Name:
Subject:
Message:
 
  Enter the characters that appear above
 
Security Holes That Run Deep 2004-12-22
michaels
Yes, IIS _doesn't_ bypass NTFS permissions - of course, it can't even do it (w/o great difficulty) - it just opens the file with ASPNET access.

The note about "MS Provide a list ... etc" - this won't help at all.

Currently they are already made publically aware of when a mistake occurs, and su...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus