Subscribe to Windows IT Pro

 

Get Newsletters

  • Get the Latest News
  • Product Updates
  • Helpful Tricks
  • Productivity Tips

Subscribe Now!

June 07, 2007 12:00 AM

Solution to IIS Security Bug Is to Upgrade?

Windows IT Pro
InstantDoc ID #96248
Rating: (0)

An authentication bug in Microsoft IIS 5.x surfaced last December. Recently Microsoft said that the fix is to upgrade to IIS 6.0, which essentially means that the company won't be producing a patch and will thereby leave IIS 5.x users vulnerable.

The problem, discovered by Joao Gouveia and John Omerni, lets someone use the search highlighting feature built into Index Server 2.0 (a part of the IIS 5.x platform) to completely bypass any authentication requirements and readily gain access to restricted content.

Microsoft's statement that such behavior in IIS 5.x "is by design" came as a shock to many administrators. Some wondered why, if that's true, this "design" doesn't exist in IIS 6.0. The shock was furthered by Microsoft's suggestion that administrators should upgrade, because in order to use IIS 6.0, administrators might also have to upgrade their server OSs to Windows Server 2003, which is a big step with considerable costs.

Potential workarounds exist to help prevent exploitation, a few of which include using URLScan, removing file mappings to .htw files, and setting file permissions. However, some say that ultimately Microsoft should issue a patch instead of forcing people to change platforms. SANS goes so far as to suggest that one possible workaround is to simply ditch IIS and migrate to Apache Web server instead.

Microsoft published an article, "Hit-highlighting does not rely on IIS authentication," about the problem on June 4, and controversy was further fueled by the fact that the company had actually provided an example in the article that essentially showed how to exploit the vulnerability. That example has since been removed from the article.

Related Content:

ARTICLE TOOLS

Comments
    There are no comments to display. Be the first one!
You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

White Papers

Get your Windows 7 deployment off to the right start by implementing PC lockdown. A locked-down environment is easier and cheaper to support since users are less likely to make unnecessary changes to the core system configuration - read more here!

Essential Guides

Is your iSCSI "lossy"? The reality is that most off-the-shelf Ethernet hardware deployed for iSCSI can lose packets, resulting in slow performance or application downtime. Learn how to assess your current iSCSI infrastructure and engineer an advanced iSCSI SAN infrastructure.

Web Seminars

What's the best way to keep your network safe from malware? In this web seminar, security expert Greg Shields suggests an alternative method to the traditional blacklisting approach that is common with anti-virus and anti-malware solutions.

eLearning Series

We bring the experts direct to you to share their real-world perspective and expertise. During each event, three sessions stream in real time, so you can learn, ask questions, and get solutions.
Upcoming event: Getting the Most with Exchange 2010 with Paul Robichaux

Subscribe to Windows IT Pro!

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.