<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>IIS 6.0 Vulnerabilities</title><link>http://msmvps.com/blogs/bernard/archive/2004/06/10/7882.aspx</link><description>About weeks ago, from a private security mailing list I get to know that recent findings on IIS 6 vulnerabilities count is 60! If you were on NTBugTraq mailing list, you might have read that as well. This actually came from Russ Copper's AUSCert presentation</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>IIS vs. Apache ?</title><link>http://msmvps.com/blogs/bernard/archive/2004/06/10/7882.aspx#16099</link><pubDate>Tue, 19 Oct 2004 06:47:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:16099</guid><dc:creator>TrackBack</dc:creator><description>&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=16099" width="1" height="1"&gt;</description></item><item><title>re: IIS 6.0 Vulnerabilities</title><link>http://msmvps.com/blogs/bernard/archive/2004/06/10/7882.aspx#8613</link><pubDate>Mon, 21 Jun 2004 15:47:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:8613</guid><dc:creator>bernard</dc:creator><description>Hi Ray,&lt;br&gt;Just set it to false, and set AspScriptErrorMessage for the error msgs.&lt;br&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=8613" width="1" height="1"&gt;</description></item><item><title>re: IIS 6.0 Vulnerabilities</title><link>http://msmvps.com/blogs/bernard/archive/2004/06/10/7882.aspx#8455</link><pubDate>Sat, 19 Jun 2004 05:58:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:8455</guid><dc:creator>bernard</dc:creator><description>Grat article with lots of good info.  I would like to script (adsutil.vbs) the change so IIS won't &amp;quot;Send detailed ASP error messages to client&amp;quot; (Default Web Site|Home Directory|Configuration|Debugging Tab).  What value do I set in the metabase (AspScriptErrorSentToBrowser)?&lt;br&gt;Thanks,&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=8455" width="1" height="1"&gt;</description></item><item><title>re: IIS 6.0 Vulnerabilities</title><link>http://msmvps.com/blogs/bernard/archive/2004/06/10/7882.aspx#8043</link><pubDate>Sun, 13 Jun 2004 00:53:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:8043</guid><dc:creator>bernard</dc:creator><description>Cool. I didn't know that. Thanks Alun.&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=8043" width="1" height="1"&gt;</description></item><item><title>re: IIS 6.0 Vulnerabilities</title><link>http://msmvps.com/blogs/bernard/archive/2004/06/10/7882.aspx#7994</link><pubDate>Sat, 12 Jun 2004 04:24:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:7994</guid><dc:creator>bernard</dc:creator><description>Just a quick note in passing on the item &amp;quot;PCT Vulnerability - CAN-2003-0719&amp;quot; - PCT is not enabled by default on Windows Server 2003, and it's difficult to imagine too many situations where an admin would enable it.  For the vulnerability to work, PCT would have to be enabled - enabling SSL is not enough.&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=7994" width="1" height="1"&gt;</description></item><item><title>re: IIS 6.0 Vulnerabilities</title><link>http://msmvps.com/blogs/bernard/archive/2004/06/10/7882.aspx#7926</link><pubDate>Fri, 11 Jun 2004 02:26:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:7926</guid><dc:creator>bernard</dc:creator><description>Kudos on a well written post :)  &lt;br&gt;&lt;br&gt;Security is the sum of all the parts and it's only as strong as it's weakest link.&lt;br&gt;&lt;br&gt;IIS 6.0 (which is yet to have it's first security release) is [b]VERY SECURE[/b].  It represents the fruitition of MS's efforts in strengthening it's security products. &lt;br&gt;&lt;br&gt;Russ is somewhat correct, in that to build a secure MS Internet or Intranet server, you need to consider all the parts (Windows, IE, etc), and thus you can arrive at dozens of required patches.  Still, IIS is just a part and saying that [b]it[/b] has the number of vulnerabilities Russ identified is misleading.&lt;br&gt;&lt;br&gt;Respectfully, Harry    &lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=7926" width="1" height="1"&gt;</description></item><item><title>IIS 6.0 Research</title><link>http://msmvps.com/blogs/bernard/archive/2004/06/10/7882.aspx#7910</link><pubDate>Thu, 10 Jun 2004 18:01:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:7910</guid><dc:creator>TrackBack</dc:creator><description>&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=7910" width="1" height="1"&gt;</description></item><item><title>re: IIS 6.0 Vulnerabilities</title><link>http://msmvps.com/blogs/bernard/archive/2004/06/10/7882.aspx#7907</link><pubDate>Thu, 10 Jun 2004 17:02:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:7907</guid><dc:creator>bernard</dc:creator><description>And then there is the obvious component that the number of vulnerabilities can be further reduced by the fact that some of the 21 W2K3 vulnerabilities just do not apply to an IIS 6.0 Server maintained by anyone with sound mind and judgement.&lt;br&gt;&lt;br&gt;As far as the 22 IE vulnerabilities, how long has it been SOP not to perform casual web browsing from a production server?&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=7907" width="1" height="1"&gt;</description></item></channel></rss>