Reported September 5, 2000 by Peter Grundl of VIGILANTe
- Microsoft Internet Information Server 4.0
By sending specifically crafted invalid URLs to the server, a denial of service attack can be launched against the Web service. According to Microsoft, the root cause resides within NT 4.0 and not IIS itself, therefore users should consider applying the patch even if IIS is not in use.
VENDOR RESPONSE
Microsoft is aware of this problem and has issued FAQ #FQ00-063, Support Online article Q271652, and a patch to correct this matter.
CREDIT
Discovered by Peter
Grundl of VIGILANTe
1 comment
Hide comments