Full Disclosure mailing list archives
RE: Frontpage Extensions Remote Command Execution
From: "mattmurphy () kc rr com" <mattmurphy () kc rr com>
Date: Wed, 12 Nov 2003 13:46:41 -0500
"Geo" <geoincidents () getinfo org> writes:
I can't believe MS sat on a root level exploit for almost a YEAR. This is trusted computing at it's best?
Well, for one, it's not root level. It allows ANONYMOUS (Guest) access to a site using FPSE for anyone who can POST to a vulnerable ISAPI extension. FPSE is not enabled by default on any OS other than Windows 2000 Server series OSes (according to MS), and is usually a security risk anyway. Also, the attacker must have the privileges on the underlying file system to run the ISAPI extension suffering from the flaw -- a privilege that is usually only granted to Authors and Administrators of the site for production servers. The result is that an anonymous user attempting to attack an IIS site using this flaw would be exploiting an already weakened config. You know, I can't believe that people criticize MS for sitting on the details of root-level holes when they don't even bother to read the bulletin. A decent admin would configure FPSE such that this flaw is a non-issue. This is because no ordinary user has a reason to be accessing FPSE's files. If FPSE is secured, this means that an attacker is getting their own privileges back. -------------------------------------------------------------------- mail2web - Check your email from the web at http://mail2web.com/ . _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- Frontpage Extensions Remote Command Execution Brett Moore (Nov 12)
- RE: Frontpage Extensions Remote Command Execution Geo. (Nov 12)
- <Possible follow-ups>
- RE: Frontpage Extensions Remote Command Execution mattmurphy () kc rr com (Nov 12)
- RE: Frontpage Extensions Remote Command Execution Geo. (Nov 12)
- Re: Frontpage Extensions Remote Command Execution Damian Gerow (Nov 12)
- Re: Frontpage Extensions Remote Command Execution Paul Schmehl (Nov 12)
- Re: Frontpage Extensions Remote Command Execution Damian Gerow (Nov 12)
- Re: Frontpage Extensions Remote Command Execution Ricky Blaikie (Nov 12)
- RE: Frontpage Extensions Remote Command Execution mattmurphy () kc rr com (Nov 12)
- Re: Frontpage Extensions Remote Command Execution Geoincidents (Nov 12)
- RE: Frontpage Extensions Remote Command Execution Nick Jacobsen (Nov 12)
- Re[2]: Frontpage Extensions Remote Command Execution Adik (Nov 13)
- RE: Frontpage Extensions Remote Command Execution Marc Maiffret (Nov 13)