Invalid URLs May Cause Denial of Service in IIS 4.0

 

Reported September 5, 2000 by
Peter Grundl of VIGILANTe

VERSIONS AFFECTED
  • Microsoft Internet Information Server 4.0

DESCRIPTION

By sending specifically crafted
invalid URLs to the server, a denial of service attack can be launched against the Web service. According to Microsoft, the root cause resides within NT 4.0 and not IIS itself, therefore users should consider applying the patch even if IIS is not in use.

VENDOR RESPONSE

Microsoft is aware of this problem and has issued FAQ #FQ00-063, Support Online article Q271652, and a patch to correct this matter.

CREDIT
Discovered by Peter Grundl of VIGILANTe

TAGS: Security
Hide comments

Comments

  • Allowed HTML tags: <em> <strong> <blockquote> <br> <p>

Plain text

  • No HTML tags allowed.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Lines and paragraphs break automatically.
Publish