Re: Alert: Microsoft Security Notification service

From: Aleph One (aleph1at_private)
Date: Wed Jul 01 1998 - 19:38:09 PDT

  • Next message: Brian Martin: "RSI.0005.05-14-98.SUN.LIBNSL (w/ errata)"

    ---------- Forwarded message ----------
    Date: Wed, 1 Jul 1998 22:30:57 -0400
    From: Russ <Russ.Cooperat_private>
    To: NTBUGTRAQat_private
    Subject: Re: Alert: Microsoft Security Notification service
    
    First, a clarification to the "Disable READ Access" workaround
    statement.
    
    You can prevent the ASP's from being viewed by disabling READ access
    within MMC for the ASPs. If you disable READ access for your entire site
    (or all files, like .gif, .htm, .etc) then those files will not be
    displayed at all.
    
    ASPs need execute only, all non-executing files need READ access to
    display normally.
    
    Second, Microsoft have been notified. Expect a fix announcement shortly.
    
    Third, I was able to talk to Bob Denny (author of O'Reilly's WebSite
    Pro), it is not affected by this exploit. I was not able to find a
    contact at Netscape to ask.
    
    Cheers,
    Russ
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 14:01:31 PDT