what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

winsd.041300.txt

winsd.041300.txt
Posted Apr 13, 2000
Authored by winsd | Site win2000mag.com

Windows Security Update - A new denial of service attack has been found in IIS 4.0 and 5.0. Sending IIS a specially coded URL that contains an excessive number of escape characters, the service is caused to perform more work than necessary, which reduces available processor cycles.

tags | denial of service, magazine
systems | windows
SHA-256 | 1e1d9f017223668bbeac99eec044089feca325a2062de4af6a754f9f6a651f23

winsd.041300.txt

Change Mirror Download
================= VERISIGN - THE INTERNET TRUST COMPANY =================
Upgrade your server security to 128-bit SSL encryption! Get VeriSign's
FREE guide, "Securing Your Web Site for Business." You will learn
everything you need to know about using 128-bit SSL to encrypt your
e-commerce transactions for serious online security.
Click here! http://www.verisign.com/cgi-bin/go.cgi?a=n046607850014000
=========================================================================

April 12, 2000 - Vanja Hrustic reported a problem with IIS 4.0 and 5.0
that could allow minor temporary denial of service attacks to be launched
against its Web services. By sending IIS a specially coded URL that
contains an excessive number of escape characters, the service is caused
to perform more work than necessary, which can temporarily reduce
available processor cycles.
The Microsoft has released a patches for IIS as well as a FAQ. An
associated Support Online was not avialable at the time of this writing.
For complete details on this risk, please visit the URL below:

* Excessive Escape Chars Can Slow IIS
http://www.ntsecurity.net/go/load.asp?iD=/security/iis4-8.htm

Thanks for subscribing to Security UPDATE.
Please tell your friends about this newsletter and alert list!

Sincerely,
The Security UPDATE Team
security@ntsecurity.net


To subscribe, go to the UPDATE home page at
http://www.win2000mag.com/update
or send a blank email to join-securityupdate@list.win2000mag.net.

To remove yourself from the list, send a blank email to
leave-securityupdate-120275L@list.win2000mag.net.

To change your email address, send a message with the sentence

set securityupdate email="new email address"

as the message text to securityupdate@list.win2000mag.net. Replace the words "new email address" with your new email address (include the quotes).

If you have questions or problems with your UPDATE subscription, please contact securityupdate@win2000mag.com. We will address your questions or problems as quickly as we can, but please allow 2 issues for resolution.

|-+-|-+-|-+-|-+-|-+-|-+-|-+-|-+-|-+-|-+-|-+-|-+-|-+-|-+-|-+-|

Copyright 2000, Windows 2000 Magazine

Login or Register to add favorites

File Archive:

July 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jul 1st
    27 Files
  • 2
    Jul 2nd
    10 Files
  • 3
    Jul 3rd
    35 Files
  • 4
    Jul 4th
    27 Files
  • 5
    Jul 5th
    18 Files
  • 6
    Jul 6th
    0 Files
  • 7
    Jul 7th
    0 Files
  • 8
    Jul 8th
    28 Files
  • 9
    Jul 9th
    44 Files
  • 10
    Jul 10th
    24 Files
  • 11
    Jul 11th
    25 Files
  • 12
    Jul 12th
    11 Files
  • 13
    Jul 13th
    0 Files
  • 14
    Jul 14th
    0 Files
  • 15
    Jul 15th
    0 Files
  • 16
    Jul 16th
    0 Files
  • 17
    Jul 17th
    0 Files
  • 18
    Jul 18th
    0 Files
  • 19
    Jul 19th
    0 Files
  • 20
    Jul 20th
    0 Files
  • 21
    Jul 21st
    0 Files
  • 22
    Jul 22nd
    0 Files
  • 23
    Jul 23rd
    0 Files
  • 24
    Jul 24th
    0 Files
  • 25
    Jul 25th
    0 Files
  • 26
    Jul 26th
    0 Files
  • 27
    Jul 27th
    0 Files
  • 28
    Jul 28th
    0 Files
  • 29
    Jul 29th
    0 Files
  • 30
    Jul 30th
    0 Files
  • 31
    Jul 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close