Microsoft IIS Unicode .asp Source Code Disclosure Vulnerability
BID:2909
Info
Microsoft IIS Unicode .asp Source Code Disclosure Vulnerability
| Bugtraq ID: | 2909 |
| Class: | Environment Error |
| CVE: |
CVE-2001-0709 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 21 2001 12:00AM |
| Updated: | Jul 11 2009 06:56AM |
| Credit: | Discovered and posted to Bugtraq by VIGILANTE <[email protected]> on June 22, 2001. |
| Vulnerable: |
Microsoft IIS 4.0 |
| Not Vulnerable: | |
Discussion
Microsoft IIS Unicode .asp Source Code Disclosure Vulnerability
A flaw exists in the handling of .asp requests. Typically when a request is made for an .asp file, IIS will identify that it is a script and run it as such. However if the host is formatted with a FAT file system and a request is made with an .asp Unicode encoded file extension, IIS may not handle the request properly and return the source code of the file.
A flaw exists in the handling of .asp requests. Typically when a request is made for an .asp file, IIS will identify that it is a script and run it as such. However if the host is formatted with a FAT file system and a request is made with an .asp Unicode encoded file extension, IIS may not handle the request properly and return the source code of the file.
Exploit / POC
Microsoft IIS Unicode .asp Source Code Disclosure Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft IIS Unicode .asp Source Code Disclosure Vulnerability
Solution:
Taken from the VIGILANTE security advisory:
"The Microsoft Security Response Center has investigated the report, but we note that the problem as reported would only affect an IIS server that has been configured to use a FAT volume. However, by design, FAT doesn't provide a security mechanism, and it's never an appropriate file system to use on a production web server. Instead, as discussed in Microsoft's best practices guides and security checklists (http://www.microsoft.com/technet/security/tools.asp), production servers should always use NTFS volumes. The reported problem does not affect systems using NTFS".
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Taken from the VIGILANTE security advisory:
"The Microsoft Security Response Center has investigated the report, but we note that the problem as reported would only affect an IIS server that has been configured to use a FAT volume. However, by design, FAT doesn't provide a security mechanism, and it's never an appropriate file system to use on a production web server. Instead, as discussed in Microsoft's best practices guides and security checklists (http://www.microsoft.com/technet/security/tools.asp), production servers should always use NTFS volumes. The reported problem does not affect systems using NTFS".
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft IIS Unicode .asp Source Code Disclosure Vulnerability
References:
References: