Threat Level: green Handler on Duty: Johannes Ullrich

SANS ISC: Microsoft puts up a blurb on their website about the IIS 0day. SANS ISC InfoSec Forums

Participate: Learn more about our honeypot network
https://isc.sans.edu/honeypot.html

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
Microsoft puts up a blurb on their website about the IIS 0day.

Microsoft has put up a response on their security blog concerning the IIS "0day".  They say that only installations in a specific "non-default" and "unsafe configuration" are vulnerable to the condition.  Also they note that if the administrator had not altered the default configuration and followed best practices in the securing of the webserver, then this exploit wouldn't work.

 

Unfortunately, we know that doesn't always wind up being the case.  Read more of their blog post here.

 

 

-- Joel Esler | http://blog.joelesler.net | http://twitter.com/joelesler

Joel

454 Posts
ISC Handler

Sign Up for Free or Log In to start participating in the conversation!