Bah! Klart man har dom senaste patcharna (se min user agent) :e
Och vad ni än tror så finns det inga buggar eller säkhål i MS produkter.
------------------
"Hey, Steve, just because you broke into Xerox's store before I did and took the TV
doesn't mean I can't go in later and steal the stereo."
-- Bill Gates, Microsoft, 3/14/89--as quoted in MacWEEK, 1/9/90 p. 23
Det borde finnas nått program som är 'linkat' till MS och deras bugg databas som kunde kolla mjukvaran och se om man saknar någon patch, ett enkelt program som funkar t.ex. att när man startar det väljer man mellan olika program som man har installerade(IIS, Explorer, OE, Windows själv) och så scannaer programmet det man har valt och säger till om några patcher saknas.
Tänk va bra att ha.
------------------
Programming today is a race between software engineers striving to build bigger and better idiot-proof programs, and the Universe trying to produce bigger and better idiots.
So far, the Universe is winning.
Dock är de bara fem stycken, på vissa låter det som det vore tiotals patchar eller hundratals när de börjar tala om att det är ett "heltidsjobb" att patcha IIS, löjligt.
Den ska dock fixa alla, så här stod det i security bullentinen:
This patch is a cumulative patch that includes the functionality of
all security patches released to date for IIS 5.0, and all patches
released for IIS 4.0 since Windows NT(r) 4.0 Service Pack 5. A
complete listing of the patches superseded by this patch is provided
below, in the section titled "Additional information about this
patch". Before applying the patch, system administrators should take
note of the caveats discussed in the same section.
In addition to including all previously released security patches,
this patch also includes fixes for five newly discovered security
vulnerabilities affecting IIS 4.0 and 5.0:
- A denial of service vulnerability that could enable an attacker
to cause the IIS 4.0 service to fail, if URL redirection has
been enabled. The "Code Red" worm generates traffic that can in
some cases exploit this vulnerability, with the result that an
IIS 4.0 machine that wasn't susceptible to infection via the
worm could nevertheless have its service disrupted by the worm.
- A denial of service vulnerability that could enable an attacker
to temporarily disrupt service on an IIS 5.0 web server. WebDAV
doesn't correctly handle particular type of very long, invalid
request. Such a request would cause the IIS 5.0 service to fail;
by default, it would automatically restart.
- A denial of service vulnerability involving the way IIS 5.0
interprets content containing a particular type of invalid MIME
header. If an attacker placed content containing such a defect
onto a server and then requested it, the IIS 5.0 service would
be unable to serve any content until a spurious entry was removed
from the File Type table for the site.
- A buffer overrun vulnerability involving the code that performs
server-side include (SSI) directives. An attacker who had the
ability to place content onto a server could include a malformed
SSI directive that, when the content was processed, would result
in code of the attacker's choice running in Local System context.
- A privilege elevation vulnerability that results because of a flaw
in a table that IIS 5.0 consults when determining whether a
process
should in-process or out-of-process. IIS 5.0 contains a table that
lists the system files that should always run in-process. However,
the list provides the files using relative as well as absolute
addressing, with the result that any file whose name matched that
of a file on the list would run in-process.
In addition, this patch eliminates a side effect of the previous IIS
cumulative patch (discussed in the Caveats section of Microsoft
Security Bulletin MS01-026) by restoring proper functioning of
UPN-style logons via FTP and W3SVC.
Nja, fem nyupptäckta säkerhetshål (sedan senaste patchen). Står ju: in addition to including all previously released security patches, this patch also includes fixes for five newly discovered security vulnerabilities.
på vissa låter det som det vore tiotals patchar eller hundratals när de börjar tala om att det är ett "heltidsjobb" att patcha IIS, löjligt
Inte heltidsjobb, men ändå omfattande. Jag vet, för det är en av mina arbetsuppgifter att patcha IIS-servrarna på vårt jobb.
Våra Apache-servrar har jag f.ö. inte behövt patcha någon gång i år. Inte boota om heller. Ett hundra procents tillgänglighet i år alltså - bra mycket mer än vad IIS-servrarna kan stoltsera med. :e
IIS får ju såklart intrycket av att ha mest buggar eftersom så många 'hackar' MS produkter, men detta är bara bra, IIS blir tätare och tätare mens servrar som Apache kan ha vem vet hur mpnga hål som aldrig upptäckts...
------------------
Programming today is a race between software engineers striving to build bigger and better idiot-proof programs, and the Universe trying to produce bigger and better idiots.
So far, the Universe is winning.
Om IIS "hackas" mer än andra servrar p.g.a. Microsoft-hat vet jag inte om jag håller med om. Men det är ju i vilket fall som helst orelevant för mig som IIS-användare. Jag är ju lika utsatt oberoende av vad angreppen beror på.
Patch NOT Found MS00-077 Q299796
Patch NOT Found MS00-079 Q276471
Patch NOT Found MS01-007 Q285851
Patch NOT Found MS01-013 Q285156
WARNING MS01-022 Q296441
Patch NOT Found MS01-025 Q296185
Patch NOT Found MS01-031 Q299553
Patch NOT Found MS01-037 Q302755
Patch NOT Found MS01-041 Q298012
Internet Information Services 5.0
Patch NOT Found MS01-025 Q296185
Patch NOT Found MS01-044 Q301625
Det där bådar inte gott va? ;)
------------------ Joakim Rosenqvist
Ah! this miasama of a rotting God!
...Ganska kul(?) att kolla på olika forum där killar i 16-17 års åldern (kvalificerad gissning) sitter och gnäller på att det är någonting fel på deras Windows 2000 Advanced Server... Reeferhttp://program.webforum.nu/wf/Forum11/HTML/000838.html
264 ms totalt · 4 externa anrop · v20260731065814-full.86ec41c2