The Register® — Biting the hand that feeds IT

Feeds

IIS buffer-overrun attack has been scripted

No skillz? No worriez

  • print
  • alert

Ensure Ease of Recovery with Asigra’s Agentless Software

A Japanese computer enthusiast named 'HighSpeed Junkie' has developed an attack script for a recently-identified unchecked buffer in the Microsoft IIS (Internet Information Services) Indexing Service ISAPI filter, which, if exploited, can yield system-level access to an intruder.

At issue is IDQ.DLL, a component of Index Server (or 'Indexing Service' in W2K) which supports administrative scripts (.IDA files) and Internet Data Queries (.IDQ files). The library is installed by default on all IIS versions and implementations.

The service need not be running for an attacker to exploit the vulnerability. So long as script mapping for .IDQ or .IDA files is present and an attacker can establish a Web session, the exploit will work.

The vulnerability was first reported by eEye Security on 18 June. The attack script was released on 21 June, and posted to the Win2KSecAdvice mailing list on 27 June.

Patches are available for NT and 2K, except for W2K Datacenter Server, whose users need to bug their OEMs. The hole will be bunged in Win-XP before it and its Raw Socket Terror are unleashed upon the public. ®

Related Links

The relevant MS security bulletin
The Win-NT 4.0 patch
The Win-2K Pro and Advanced Server patch

Requirements Checklist for Choosing a Cloud Backup and Recovery Service Provider

More from The Register

Bjarne Again: Hallelujah for C++
Plus: Now officially OK to admit you never used STL algorithms
Interwebs taunt Sir Jony over Apple eye candy makeover
Hey Ive, Ive... add more unicorns, willya?
SCO vs. IBM battle resumes over ownership of Unix
Zombie lawsuit back and wants to suck the brains out of Linux
Red Hat to ditch MySQL for MariaDB in RHEL 7
So long, Oracle! Don't let the door hit you on the way out
Shy? Socially inadequate? Fiddling with your phone could help
App 'tells the brutal truth' about social inadequates' chatup lines
Java EE 7 melds HTML5 with enterprise apps
New release arrives with GlassFish, NetBeans support
 breaking news
'Office Facebook' firm Tibbr wants you to PAY for mobe-meetings app
Great idea. Punters won't cough for it though
 breaking news
The only Waze is Google: Ad giant tipped to gobble map app 'for $1.3bn'
Pac-Man-satnav-ish upstart in bidding war with Apple, Facebook
 breaking news
PM Cameron calls for modern, programmable computers! (We think)
IT education musings to G8 chiefs to mystify IT industry
Apple at WWDC: Sleek new iOS, death of the big cats, pint-sized Mac Pro
CEO Cook: 'The biggest change to iOS since the introduction of the iPhone'