Advertisement
Promo

Network management Toolkit in association with http://ad.doubleclick.net/clk;217618582;14453422;e?http://www.citrix.com/lang/English/lp/lp_1688615.asp

US Report: Microsoft warns of IIS security hole

ZDNN, US ZDNet US

Published: 20 Jul 1998 06:40 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Remote Data Service is installed by default when IIS 4.0 is implemented using the Microsoft Windows NT Option Pack. Microsoft's IIS development team discovered that a component of Remote Data Service, DataFactory, allows an intruder who has gained possession of a password and the name of a target database to submit a query to the database remotely and get results.

Microsoft aired the exposure to its IIS developers through a July 15 bulletin as part of its new Security Advisor Notification Service, which it began two weeks ago.

"Security issues will come up. It's important to get timely and accurate information" into the hands of customers, said Karan Khanna, Windows NT security product manager.

Khanna said no known cases have come up of malicious hackers exploiting the hole. In addition to subscribers to the notification service, the bulletin is posted at the Web site.

Microsoft also notified the Computer Emergency Response Team at Carnegie Mellon University and the Department of Energy.

The problem can be corrected when a systems administrator deletes three keys from the IIS server registry. Khanna termed the problem "a configuration issue, not a security issue," since no breaches have occurred. But he acknowledged that the hole is created inadvertently through installation of IIS 4.0 with the NT Option Pack, which installs DataFactory as a default means of remote access to databases. Any relational database accessed through the Open Database Connect set of drivers could be subject to an unauthorised query through DataFactory.

Khanna said such a move was unlikely because the intruder would have to gain legitimate passwords for the local site. But password-guessing dictionaries or common-password-guessing programs have been used at sites in the past to come up with a working password, as noted elsewhere on the Microsoft Security Advisor site.

Microsoft's Security Advisor Notification Service can be reached at www.microsoft.com/security

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
27 out of 55 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:














Related Citrix Resources

Achieving the lowest server virtualization TCO

Consolidation through server virtualization is a powerful agent for datacenter change, but...

Achieving the lowest server virtualization Total Cost of Ownership

Consolidation through server virtualization is a powerful agent for datacenter change, but...

Citrix XenDesktop: The Best Desktop Delivery System For Today's Demanding Business Needs

Whether you're considering your first virtual desktop solution or trying to salvage an existing...

Desktop Virtualization: A buyer's checklist

Desktop virtualization should do more than just move desktop management to the datacenter—its real...

Five reasons why you need Citrix Essentials for Hyper-V now

This paper explores common challenges associated with server virtualization deployments and the...

See All White Papers

Video icon

Video

On The Road Blog

Official Organizations Losing Data

How does this article from earlier today make you feel? How many more government, health service, or military officials are going to lose pen drives, DVDs, USB hard disks and even entire... More

2 comments

Using Bluetooth on Linux

I have mentioned before that I use a number of Bluetooth peripherals with my portable computers. This is one of those things where, the more I use it the more I like it. I've now... More

Post a comment

Toshiba JournE Touch

Look around the room at any meeting these days and you see the back of a lot of laptop screens, with as many people catching up on email as taking notes or doing relevant research.... More

1 comment

Win a BlackBerry with Vlingo voice recognition

Win a BlackBerry with Vlingo voice recognition

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters