exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

winsd.041300.txt

winsd.041300.txt
Posted Apr 13, 2000
Authored by winsd | Site win2000mag.com

Windows Security Update - A new denial of service attack has been found in IIS 4.0 and 5.0. Sending IIS a specially coded URL that contains an excessive number of escape characters, the service is caused to perform more work than necessary, which reduces available processor cycles.

tags | denial of service, magazine
systems | windows
SHA-256 | 1e1d9f017223668bbeac99eec044089feca325a2062de4af6a754f9f6a651f23

winsd.041300.txt

Change Mirror Download
================= VERISIGN - THE INTERNET TRUST COMPANY =================
Upgrade your server security to 128-bit SSL encryption! Get VeriSign's
FREE guide, "Securing Your Web Site for Business." You will learn
everything you need to know about using 128-bit SSL to encrypt your
e-commerce transactions for serious online security.
Click here! http://www.verisign.com/cgi-bin/go.cgi?a=n046607850014000
=========================================================================

April 12, 2000 - Vanja Hrustic reported a problem with IIS 4.0 and 5.0
that could allow minor temporary denial of service attacks to be launched
against its Web services. By sending IIS a specially coded URL that
contains an excessive number of escape characters, the service is caused
to perform more work than necessary, which can temporarily reduce
available processor cycles.
The Microsoft has released a patches for IIS as well as a FAQ. An
associated Support Online was not avialable at the time of this writing.
For complete details on this risk, please visit the URL below:

* Excessive Escape Chars Can Slow IIS
http://www.ntsecurity.net/go/load.asp?iD=/security/iis4-8.htm

Thanks for subscribing to Security UPDATE.
Please tell your friends about this newsletter and alert list!

Sincerely,
The Security UPDATE Team
security@ntsecurity.net


To subscribe, go to the UPDATE home page at
http://www.win2000mag.com/update
or send a blank email to join-securityupdate@list.win2000mag.net.

To remove yourself from the list, send a blank email to
leave-securityupdate-120275L@list.win2000mag.net.

To change your email address, send a message with the sentence

set securityupdate email="new email address"

as the message text to securityupdate@list.win2000mag.net. Replace the words "new email address" with your new email address (include the quotes).

If you have questions or problems with your UPDATE subscription, please contact securityupdate@win2000mag.com. We will address your questions or problems as quickly as we can, but please allow 2 issues for resolution.

|-+-|-+-|-+-|-+-|-+-|-+-|-+-|-+-|-+-|-+-|-+-|-+-|-+-|-+-|-+-|

Copyright 2000, Windows 2000 Magazine

Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close