Microsoft IIS 4.0 IISADMPWD Proxied Password Attack
BID:2110
Info
Microsoft IIS 4.0 IISADMPWD Proxied Password Attack
| Bugtraq ID: | 2110 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Feb 09 1998 12:00AM |
| Updated: | Feb 09 1998 12:00AM |
| Credit: | Posted to BugTraq on February 9, 1998 by David Litchfield <[email protected]> |
| Vulnerable: |
Microsoft IIS 4.0 |
| Not Vulnerable: | |
Exploit / POC
Microsoft IIS 4.0 IISADMPWD Proxied Password Attack
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft IIS 4.0 IISADMPWD Proxied Password Attack
Solution:
Microsoft refers to this as a feature for network administrators, but do point out in article Q184619 that it is a potential security risk. According to the article, "You can configure a site to support password changes by setting the following properties on the site: PasswordCacheTTL, PasswordChangeFlags and PasswordExpirePrenotifyDays. Refer to the IIS documentation for more details on these properties." It may be prudent to disable this feature if it is accessible by untrusted machines.
Solution:
Microsoft refers to this as a feature for network administrators, but do point out in article Q184619 that it is a potential security risk. According to the article, "You can configure a site to support password changes by setting the following properties on the site: PasswordCacheTTL, PasswordChangeFlags and PasswordExpirePrenotifyDays. Refer to the IIS documentation for more details on these properties." It may be prudent to disable this feature if it is accessible by untrusted machines.
References
Microsoft IIS 4.0 IISADMPWD Proxied Password Attack
References:
References: