<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Server: Microsoft-IIS/7.0\r\n  : IIS</title><link>http://msmvps.com/blogs/bernard/archive/tags/IIS/default.aspx</link><description>Tags: IIS</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>Security Alerts - December 2009</title><link>http://msmvps.com/blogs/bernard/archive/2009/12/11/security-alerts-december-2009.aspx</link><pubDate>Fri, 11 Dec 2009 03:36:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1744754</guid><dc:creator>qbernard</dc:creator><slash:comments>3</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bernard/rsscomments.aspx?PostID=1744754</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bernard/commentapi.aspx?PostID=1744754</wfw:comment><comments>http://msmvps.com/blogs/bernard/archive/2009/12/11/security-alerts-december-2009.aspx#comments</comments><description>Recently, Microsoft released the December security bulletin , and one of the patches related to IIS. Meant to blog about this earlier but Nazim from IIS team beat me to it :) Been seeing lot of discussions online and patch management related mailing list...(&lt;a href="http://msmvps.com/blogs/bernard/archive/2009/12/11/security-alerts-december-2009.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1744754" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bernard/archive/tags/IIS+Downloads/default.aspx">IIS Downloads</category><category domain="http://msmvps.com/blogs/bernard/archive/tags/IIS+Links/default.aspx">IIS Links</category><category domain="http://msmvps.com/blogs/bernard/archive/tags/IIS+KBs/default.aspx">IIS KBs</category><category domain="http://msmvps.com/blogs/bernard/archive/tags/IIS/default.aspx">IIS</category></item><item><title>Warning: Authorization - Cannot verify access to path (C:\inetpub\wwwroot\).</title><link>http://msmvps.com/blogs/bernard/archive/2009/11/04/warning-authorization-cannot-verify-access-to-path-c-inetpub-wwwroot.aspx</link><pubDate>Wed, 04 Nov 2009 09:51:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1737592</guid><dc:creator>qbernard</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bernard/rsscomments.aspx?PostID=1737592</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bernard/commentapi.aspx?PostID=1737592</wfw:comment><comments>http://msmvps.com/blogs/bernard/archive/2009/11/04/warning-authorization-cannot-verify-access-to-path-c-inetpub-wwwroot.aspx#comments</comments><description>I&amp;#39;m sure you have seen the below warning message many times with IIS 7+ The server is configured to use pass-through authentication with a built-in account to access the specified physical path. However, IIS Manager cannot verify whether the built...(&lt;a href="http://msmvps.com/blogs/bernard/archive/2009/11/04/warning-authorization-cannot-verify-access-to-path-c-inetpub-wwwroot.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1737592" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bernard/archive/tags/IIS+Links/default.aspx">IIS Links</category><category domain="http://msmvps.com/blogs/bernard/archive/tags/IIS+FAQs/default.aspx">IIS FAQs</category><category domain="http://msmvps.com/blogs/bernard/archive/tags/IIS/default.aspx">IIS</category></item><item><title>IIS DebugDiag x64 is out</title><link>http://msmvps.com/blogs/bernard/archive/2009/10/30/iis-debugdiag-x64-is-out.aspx</link><pubDate>Fri, 30 Oct 2009 09:07:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1736298</guid><dc:creator>qbernard</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bernard/rsscomments.aspx?PostID=1736298</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bernard/commentapi.aspx?PostID=1736298</wfw:comment><comments>http://msmvps.com/blogs/bernard/archive/2009/10/30/iis-debugdiag-x64-is-out.aspx#comments</comments><description>Previously, the x86 version you are able to debug 32bit worker processes running on 32/64bit OSes, with this release - you can now debug a full 64bit worker processes. Here&amp;#39;s the link at Microsoft download, and addtional note for x64 release Notes...(&lt;a href="http://msmvps.com/blogs/bernard/archive/2009/10/30/iis-debugdiag-x64-is-out.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1736298" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bernard/archive/tags/IIS+News/default.aspx">IIS News</category><category domain="http://msmvps.com/blogs/bernard/archive/tags/IIS+Downloads/default.aspx">IIS Downloads</category><category domain="http://msmvps.com/blogs/bernard/archive/tags/IIS+Links/default.aspx">IIS Links</category><category domain="http://msmvps.com/blogs/bernard/archive/tags/IIS/default.aspx">IIS</category></item><item><title>Token Kidnapping - Fixed</title><link>http://msmvps.com/blogs/bernard/archive/2009/04/14/token-kidnapping-fixed.aspx</link><pubDate>Tue, 14 Apr 2009 14:09:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1687626</guid><dc:creator>qbernard</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bernard/rsscomments.aspx?PostID=1687626</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bernard/commentapi.aspx?PostID=1687626</wfw:comment><comments>http://msmvps.com/blogs/bernard/archive/2009/04/14/token-kidnapping-fixed.aspx#comments</comments><description>A year ago... Cesar Cerrudo presented a serious vulnerability via evalvation of privilege involving the NetworkService or LocalService account specific to IIS worker process. Although Microsoft addressed this in April last year, but it was more towards...(&lt;a href="http://msmvps.com/blogs/bernard/archive/2009/04/14/token-kidnapping-fixed.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1687626" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bernard/archive/tags/IIS+News/default.aspx">IIS News</category><category domain="http://msmvps.com/blogs/bernard/archive/tags/IIS+KBs/default.aspx">IIS KBs</category><category domain="http://msmvps.com/blogs/bernard/archive/tags/IIS/default.aspx">IIS</category></item><item><title>IIS Insider - Zzz...</title><link>http://msmvps.com/blogs/bernard/archive/2009/01/22/iis-insider-zzz.aspx</link><pubDate>Thu, 22 Jan 2009 05:17:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1664572</guid><dc:creator>qbernard</dc:creator><slash:comments>2</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bernard/rsscomments.aspx?PostID=1664572</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bernard/commentapi.aspx?PostID=1664572</wfw:comment><comments>http://msmvps.com/blogs/bernard/archive/2009/01/22/iis-insider-zzz.aspx#comments</comments><description>Errr.... 2 yrs ago I told you I wrote the last ever IIS Insider column for MS!!! Chris Adam back then even put up a notice to inform everyone. Believe me, the URL is valid back then.... after MS site reorg, yeah! happen every quarter you know :) so it...(&lt;a href="http://msmvps.com/blogs/bernard/archive/2009/01/22/iis-insider-zzz.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1664572" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bernard/archive/tags/IIS+News/default.aspx">IIS News</category><category domain="http://msmvps.com/blogs/bernard/archive/tags/IIS/default.aspx">IIS</category></item><item><title>IIS Insider - September 2006 Issue - Repost</title><link>http://msmvps.com/blogs/bernard/archive/2009/01/21/iis-insider-sep-2006.aspx</link><pubDate>Wed, 21 Jan 2009 00:32:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1664535</guid><dc:creator>qbernard</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bernard/rsscomments.aspx?PostID=1664535</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bernard/commentapi.aspx?PostID=1664535</wfw:comment><comments>http://msmvps.com/blogs/bernard/archive/2009/01/21/iis-insider-sep-2006.aspx#comments</comments><description>IIS Insider: September 2006 By Bernard Cheah, IIS Insider is a monthly column designed to answer your questions on how to troubleshoot and make the most of Microsoft Internet Information Services (IIS). The example companies, organizations, products,...(&lt;a href="http://msmvps.com/blogs/bernard/archive/2009/01/21/iis-insider-sep-2006.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1664535" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bernard/archive/tags/IIS+News/default.aspx">IIS News</category><category domain="http://msmvps.com/blogs/bernard/archive/tags/IIS/default.aspx">IIS</category></item><item><title>IIS KBs - June 2008</title><link>http://msmvps.com/blogs/bernard/archive/2008/07/30/iis-kbs-june-2008.aspx</link><pubDate>Wed, 30 Jul 2008 06:10:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1642656</guid><dc:creator>qbernard</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bernard/rsscomments.aspx?PostID=1642656</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bernard/commentapi.aspx?PostID=1642656</wfw:comment><comments>http://msmvps.com/blogs/bernard/archive/2008/07/30/iis-kbs-june-2008.aspx#comments</comments><description>950573 FIX: Application domains restart unexpectedly in Internet Information Services 7.0 954874 IIS binds to all IP addresses on a server when you install IIS 7.0 on Windows Server 2008 954872 How to create and manage configuration backups in Internet...(&lt;a href="http://msmvps.com/blogs/bernard/archive/2008/07/30/iis-kbs-june-2008.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1642656" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bernard/archive/tags/IIS+KBs/default.aspx">IIS KBs</category><category domain="http://msmvps.com/blogs/bernard/archive/tags/IIS/default.aspx">IIS</category></item><item><title>How to Detect, Identify and Defend against SQL Injection?</title><link>http://msmvps.com/blogs/bernard/archive/2008/06/25/how-to-detect-identify-and-defend-against-sql-injection.aspx</link><pubDate>Wed, 25 Jun 2008 12:40:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1637546</guid><dc:creator>qbernard</dc:creator><slash:comments>2</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bernard/rsscomments.aspx?PostID=1637546</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bernard/commentapi.aspx?PostID=1637546</wfw:comment><comments>http://msmvps.com/blogs/bernard/archive/2008/06/25/how-to-detect-identify-and-defend-against-sql-injection.aspx#comments</comments><description>&lt;p&gt;&lt;a class="" href="http://en.wikipedia.org/wiki/SQL_injection" target="_blank"&gt;&lt;strong&gt;SQL Injection&lt;/strong&gt;&lt;/a&gt;&amp;nbsp;has been around for many years :) and you probably get over 3 million results when you googled the term. so why is it so HOT now? Well, not so long ago some folks&amp;nbsp;(don&amp;#39;t ask me who!!, go read)&amp;nbsp;were claiming that it was an IIS exploit, etc. Hence, all IIS web servers are subjected to this exploit, but the fact is that it has nothing to do with IIS, it is Web application related, so if you have a web/database application that running on Apache or even IBM Websphere, etc, you are subjected to the attack as well when user inputs are not properly validated. In short, the attack uses these input as the command window/line to issue specify command to the database that &amp;quot;not suppose&amp;quot; to happen via the application interface. For example, user can easily manipulate the database scheme and data, or user can even gain further access via the database system to the actual operating system level access.&lt;/p&gt;
&lt;p&gt;Anyway, Microsoft just released a &lt;a class="" href="http://www.microsoft.com/technet/security/advisory/954462.mspx" target="_blank"&gt;&lt;strong&gt;security advisory&lt;/strong&gt;&lt;/a&gt; on how to detect via a &lt;a class="" href="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2008/06/23/finding-sql-injection-with-scrawlr.aspx" target="_blank"&gt;&lt;strong&gt;free scanner&lt;/strong&gt;&lt;/a&gt; from HP, how to protect at IIS level via &lt;a class="" href="http://learn.iis.net/page.aspx/473/using-urlscan" target="_blank"&gt;&lt;strong&gt;URLSCAN 3.0&lt;/strong&gt;&lt;/a&gt; :) take note that this is still beta and how to identify it at coding level via &lt;a class="" href="http://support.microsoft.com/kb/954476" target="_blank"&gt;&lt;strong&gt;Microsoft Source Code Analyzer for SQL Injection&lt;/strong&gt;&lt;/a&gt;, take note this analyzer only works for ASP.&lt;/p&gt;
&lt;p&gt;While the above is useful and helpful, you probably want to educate your developers on secure coding by implementing proper input validation before the input is process by the web or database system. The &lt;a class="" href="http://www.microsoft.com/technet/security/advisory/954462.mspx" target="_blank"&gt;&lt;strong&gt;advisory&lt;/strong&gt;&lt;/a&gt; contains a&amp;nbsp;lot more information about the attack technique, best practices and more. So make sure you forward the details to your developers!!!&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1637546" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bernard/archive/tags/IIS+News/default.aspx">IIS News</category><category domain="http://msmvps.com/blogs/bernard/archive/tags/IIS+Links/default.aspx">IIS Links</category><category domain="http://msmvps.com/blogs/bernard/archive/tags/IIS/default.aspx">IIS</category></item></channel></rss>