Subscribe to Windows IT Pro
January 29, 2001 12:00 AM

HTR Files Expose ASP File Content on IIS

Windows IT Pro
InstantDoc ID #19800
Rating: (0)

Reported January 29, 2001, by Microsoft.

VERSIONS AFFECTED

  • Internet Information Server 4.0

  • Internet Information Server 5.0 

DESCRIPTION

Microsoft has issued a patch for a new variation of the “File Fragment Reading via .HTR” vulnerability. A malicious user can use this vulnerability to read .asp files.

VENDOR RESPONSE

Microsoft has released a security bulletin, MS01-004. Microsoft recommends that users disable .htr functionality and not store sensitive information on a Web server.

CREDIT
Discovered by Microsoft.

 

Related Content:

ARTICLE TOOLS

Comments
    There are no comments to display. Be the first one!
You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.