Vulnerability Development mailing list archives

Re: CR II - winME? confirmation? (Slightly OT)


From: "Grab Raham" <grabraham () hotmail com>
Date: Tue, 07 Aug 2001 17:34:18

I think the something obvious may be for a Web based worm to spread it needs a web server to attack. The machine may indeed be vulnerable to other shinanagins via idq.dll but without the webserver and the webserver's inclusion of the idq.dll a machine is not vulnerable to the WORM wich is what the advisories are speaking about.

Shawn

Hi All,
....
Wouldn’t that make ANY system with the indexing service on it just as vulnerable as systems with IIS? Am I overlooking something obvious here?

Regards,
Amer Karim
Nautilis Information Systems
e-mail: amerk () telus net, mamerk () hotmail com



_________________________________________________________________
Get your FREE download of MSN Explorer at http://explorer.msn.com/intl.asp


Current thread: