NT Using ASP And FSO To Read Server Files Vulnerability
BID:230
Info
NT Using ASP And FSO To Read Server Files Vulnerability
| Bugtraq ID: | 230 |
| Class: | Access Validation Error |
| CVE: |
CVE-1999-1375 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Feb 11 1999 12:00AM |
| Updated: | Jul 11 2009 12:16AM |
| Credit: | This vulnerability was posted to NTBugtraq by Gary Geisbert <[email protected]>. |
| Vulnerable: |
Microsoft IIS 4.0 Microsoft IIS 3.0 |
| Not Vulnerable: | |
Solution / Fix
NT Using ASP And FSO To Read Server Files Vulnerability
Solution:
Joel Maslak <[email protected]> suggests Applying appropriate NTFS permissions to limit the access to given to the IUSR_machinename account. For multiple virtual web servers, run each virtual server under a different user account.
Russ Cooper <[email protected]> recommends disabling the "Allow Parent Paths" option via Internet Services Manager.
Solution:
Joel Maslak <[email protected]> suggests Applying appropriate NTFS permissions to limit the access to given to the IUSR_machinename account. For multiple virtual web servers, run each virtual server under a different user account.
Russ Cooper <[email protected]> recommends disabling the "Allow Parent Paths" option via Internet Services Manager.