ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Industry watch Toolkit

FrontPage flaw puts servers in jeopardy

Published: 26 Sep 2002 07:43 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft warned Web site administrators on Wednesday that a flaw in its FrontPage extensions could allow an attacker to take control of their servers or cause the computers to seize up.

In its 53rd advisory for the year, the software giant said a vulnerability in the SmartHTML interpreter could be exploited to cause a denial-of-service attack on the Web server if the computer had FrontPage Server Extensions 2000 running. For FrontPage Server Extensions 2002, the flaw could result in the attacker running the code of their choice, essentially taking control of the server.

"If a request for a certain type of Web file is made in a particular way... (it could cause) the SmartHTML interpreter to cycle endlessly, consuming all the server's CPU availability," according to Microsoft's advisory.

The company urged administrators to apply the patch for the problem or run the Internet Information Server lockdown tool, a security application that disables many of the potentially dangerous functions in Microsoft's IIS Web server.

Despite launching its Trustworthy Computing initiative in January, the software giant has racked up more than 70 vulnerabilities outlined in 53 advisories this year. Last week, Microsoft revealed three flaws in its Java virtual machine software.

The same day, the US government unveiled the National Strategy for Securing Cyberspace. While the strategy urged companies and security researchers to solve vulnerability issues quickly and discretely, it didn't highlight software companies' problems in eliminating such problems.

Microsoft credited Digital Defense Services for finding the problem.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
47 out of 98 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Project Manager (Online, End-To-End Web-Site builds )

Project Manager to work for a global Media & Publishing organisation. Our client has offices world-wide and have over 300 publications and related ...

Security Consultant Ethical Hacking / Penetration Testing - London

Responsibilities: - Deliver security assessment services including network scanning, vulnerability testing, penetration testing, search engine ...

ASP.NET (C#) Contract with Defense in Crawley

Our defense client based in Crawley require a Security cleared Contractor to come on board for a 6 month contract. Will need to have full life cycle ...

Discussions

harpless harpless

SAP goes big business

Friday 25 July 2008, 6:17 PM

1 comment
pjc158 pjc158

Will Drizzle rain on Sun's MySql

Friday 25 July 2008, 5:30 PM

1 comment
pjc158 pjc158

Show me the money!

Friday 25 July 2008, 5:18 PM

5 comments

Featured Talkback

When all is said, if Microsoft produce the best product people will buy it and thats a good thing. If people have to buy their product because no one else can produce an alternative, only because interoperability protocols are kept secret, then thats a bad thing.

By: pround

Read full story:
EU court crushes Microsoft's antitrust appeal