Slashdot Mirror


WebDAV Buffer Overflow Attack Compromises IIS 5.0

rf0 writes "Well CERT is reporting a new overflow attack for IIS 5.0. Microsoft has released a bulletin. Better download those patches and fix another security hole." According to this CNET story, Microsoft says that this is already being exploited, at the very least since last Wednesday.

14 of 367 comments (clear)

  1. yup by Anonymous Coward · · Score: 4, Funny

    (looks at watch) its monday again... time to go patch my IIS

    1. Re:yup by Groo+Wanderer · · Score: 4, Funny

      Having to watch over a handfull of IIS machines for several companies, I can say, with some authority, that if you only patch weekly, you are in trouble. MS often releases several critical patches per week, get on the ball.

      -Charlie

      (This was origionally menat to be sarcasm, but then I wnet to the windows update and looked at the entire patch list, not the rollups. It really is as bad as I was thinking. As that great philosopher Pepe LaPew says, *LeSigh*.)

  2. Patch? by Iamthefallen · · Score: 4, Funny
    Better download those patches and fix another security hole.

    Well duh, "patch my IIS", it's monday isn't it?

    --
    Wax-Museum Fire Results In Hundreds Of New Danny DeVito Statues
    1. Re:Patch? by mrjive · · Score: 5, Funny

      More like "every day that ends in -day"

      --
      If you can't beat them, arrange to have them beaten. -George Carlin
  3. Another day, another Microsoft bug by RighteousFunby · · Score: 4, Funny

    When they get a bug free Windows, they'll have to put some in just so bored /. readers have something to laugh at....

  4. Bah, the Internet by Captain+Beefheart · · Score: 5, Funny

    I don't know why anyone uses it anymore. I'm switching back to Morse Code. Who's with me?

    1. Re:Bah, the Internet by Anonvmous+Coward · · Score: 5, Funny

      "I don't know why anyone uses it anymore. I'm switching back to Morse Code. Who's with me?"

      Shut the ..-. up!

      =D

  5. OMG! by Anonymous Coward · · Score: 4, Funny

    Cue 2,000 microsoft bashing messages...

    1. Re:OMG! by NewbieProgrammerMan · · Score: 5, Funny

      I hope you don't have a static buffer allocated for those messages, because it'll....ummm...overflow.

      --
      [b.belong('us') for b in bases if b.owner() == 'you']
  6. I'd uninstall it but... by OffTheLip · · Score: 5, Funny

    I was ready to uninstall IIS when it occured to me that Exchange 2K needs it. I was ready to uninstall Exchange 2K when I realized users would not be able to function. Whew, luckily I came to my senses...

  7. Re:Again... by zzxc · · Score: 5, Funny

    >Why is the code that the web server has access to
    >change allowed to take over the system?

    Because it is "trusted".

  8. Re:This is news? by mmol_6453 · · Score: 5, Funny

    Between getting rooted and being automatically subject to license agreements, I'd rather get rooted.

    --
    What's this Submit thingy do?
  9. CERT can save money... by huhmz · · Score: 4, Funny

    If CERT would just move their headquarters to the IIS devs room in redmond, that would probably save a lot of money for CERT. They should be a part of the regular IIS dev team.

  10. Exploited! by DarkHelmet · · Score: 4, Funny
    Microsoft says that this is already being exploited, at the very least since last Wednesday.

    And I thought that Penguin on the Microsoft home page looked at little out of place.

    --
    /^[A-Z0-9._%+-]+@[A-Z0-9.-]+\.[A-Z]{2,4}$/i