IIS WEBDAV Denial of Service attacks

From: Mark Litchfield (markat_private)
Date: Thu May 29 2003 - 11:51:11 PDT

  • Next message: bugzillaat_private: "[Full-Disclosure] [RHSA-2003:181-01] Updated ghostscript packages fix vulnerability"

    Hi All,
    
    I won't bother posting my advisories for the DOS issues here as SPIDynamics
    SPI Labs ( http://www.spidynamics.com/spilabs.html ) have already released
    theirs.  In case you missed their postings, and you have deployed IIS 4.0 /
    IIS 5.0 and IIS 5.1 as your chosen web server, to obtain the patch please
    visit
    http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/
    bulletin/MS03-018.asp
    
    Checks for these issues have been incorporated into Typhon III -
    http://www.ngssoftware.com/products/typhon.htm
    
    All the best
    
    Mark Litchfield
    NGS Software Ltd
    http://www.ngssoftware.com/
    Tel: +44 208 40 100 70 (London)
    Tel: +44 1241 431 267
    Mobile: +44 790 069 5236
    Email: markat_private
    



    This archive was generated by hypermail 2b30 : Fri May 30 2003 - 00:33:15 PDT