DSI NETWORKS & SOLUTIONS
  Home     Forum  
Register   Login  
   Forum:
  Active TopicsActive Topics  Display List of Forum MembersMemberlist  Search The ForumSearch  HelpHelp
  RegisterRegister  LoginLogin
Security Alerts
 Forum-Security Alerts
Subject Topic: IIS 5/6 FTP DoS stack exhaustion ls -R * Post ReplyPost New Topic
Author
Message << Prev Topic | Next Topic >>
DSI-Tech
Admin Group
Admin Group


Joined: 25-January-2003
Posts: 38

Online Status: Offline
Posted: 08-September-2009 at 10:29 | IP Logged Quote DSI-Tech

Alert
A security exploit based on an unchecked buffer in the Microsoft IIS5/6 (Windows 2000/2003/XP) has been discovered and publicly disclosed on 05/09/09.
The exploit leads to process crash of the entire IIS subsystem, including Web sites.
Microsoft has not released any comment or work-around in the interim.
 
Recommendation
Check IIS5 and IIS6 FTP deployments and ensure the following work around is in place:
 
Exploit:
Several proof of concept are available on the Internet
Running the ls "-R */../" command after login (anonymous or any user) will cause IIS (inlcuding the Webserver components) to reset. If the services are set to manual, they will not restart.
This occurs if:
-subdirectories exist in the FTP directory the user is logged onto.
-user has read rigths to these subdirectories
-user issues the above command
 
Work-around:
1. Ensure IIS FTP isolates users to their own home-directories (http://support.microsoft.com/?id=555018)
2. Ensure users (including anonymous) DO NOT HAVE NTFS RIGHTS on any subdirectories, nor the ability to create subirectories. This can be achieved by ensuring the following rights are applied to THIS DIRECTORY and FILES ONLY
- IUSR_(machinename) (or equivalent Anonymous account) and CREATOR OWNER
- Traverse Folder/Execute File
- List Folder / Read Data
- Read Attributes
- Read Extended Attributes
- Create Files /Write Data
- Read Permissions
-CREATOR OWNER
 
 
Risk assessment:
Initial assessment of this risk is LOW at this stage, as there are no known automated exploits active on the Internet.
Back to Top View DSI-Tech's Profile Search for other posts by DSI-Tech
 

If you wish to post a reply to this topic you must first login
If you are not already registered you must first register

  Post ReplyPost New Topic
Printable version Printable version

Forum Jump
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot delete your posts in this forum
You cannot edit your posts in this forum
You cannot create polls in this forum
You cannot vote in polls in this forum

Powered by Web Wiz Forums version 7.92
Copyright ©2001-2004 Web Wiz Guide
* Webmaster |  ©1999-2009 DSI NETWORKS & SOLUTIONS |  Site Launched: 21 Oct 2004
Powered By EzASPSite v2.0 RC3a