Feeds

Major MS Web Server security hole exposed, plugged

Bug-fix terrorism? Whatever next?

  • alert
  • submit to reddit

Maximizing your infrastructure through virtualization

Security outfit eEye has roused Microsoft's ire and garnered itself some cheap publicity by going public with information on what it says is a serious security flaw in Microsoft's Internet Information Server (IIS) 4.0. The move hasn't helped the company's relationship with Microsoft any, but it seems to have triggered the appearance of a swift patch, full fix to follow. According to eEye the flaw allows arbitrary code to be run on any web server running IIS 4.0, and by using a buffer overflow bug in the software attackers can remotely execute code to enable access to all data on the server." So it's a serious one, although Microsoft says it hasn't had any reports of the security hole being used so far. eEye accuses Microsoft of failing to give the problem the attention it deserved. The company claims to have hassled MS for days, but "after the fifth day of reporting the bug to Microsoft, they stopped responding to our emails." So the company went public with the problem three days later, as an attempt to force Microsoft's hand. Microsoft swiftly posted a patch, but accuses eEye of irresponsibility in publicising a problem before a fix had been found. There's some justification in that, but there's also some in the view that being able to announce "we've found a hole, but we fixed it" is better than having to confirm "Yike, there's a huge security hole in our product." ®

Top three mobile application threats

More from The Register

next story
BBC goes offline in MASSIVE COCKUP: Stephen Fry partly muzzled
Auntie tight-lipped as major outage rolls on
iPad? More like iFAD: We reveal why Apple fell into IBM's arms
But never fear fanbois, you're still lapping up iPhones, Macs
Nadella: Apps must run on ALL WINDOWS – PCs, slabs and mobes
Phone egg, meet desktop chicken - your mother
White? Male? You work in tech? Let us guess ... Twitter? We KNEW it!
Grim diversity numbers dumped alongside Facebook earnings
Microsoft: We're making ONE TRUE WINDOWS to rule us all
Enterprise, Windows still power firm's shaky money-maker
HP, Microsoft prove it again: Big Business doesn't create jobs
SMEs get lip service - what they need is dinner at the Club
ITC: Seagate and LSI can infringe Realtek patents because Realtek isn't in the US
Land of the (get off scot) free, when it's a foreign owner
Dude, you're getting a Dell – with BITCOIN: IT giant slurps cryptocash
1. Buy PC with Bitcoin. 2. Mine more coins. 3. Goto step 1
There's NOTHING on TV in Europe – American video DOMINATES
Even France's mega subsidies don't stop US content onslaught
prev story

Whitepapers

Top three mobile application threats
Prevent sensitive data leakage over insecure channels or stolen mobile devices.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Top 8 considerations to enable and simplify mobility
In this whitepaper learn how to successfully add mobile capabilities simply and cost effectively.
Application security programs and practises
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
The Essential Guide to IT Transformation
ServiceNow discusses three IT transformations that can help CIO's automate IT services to transform IT and the enterprise.