[200 OK]: A Port80 Software Blog

We're all 200 OK: Web, HTTP and IIS Insights
posts - 199, comments - 725, trackbacks - 95

First IIS patch of '05 and Helpful, Courteous Spyware

Microsoft released its first patches of the year today.

One important level patch affects IIS 5, 5.1 and 6.0 if you use the Indexing Service (formerly Index Server) and could be used to take over the server. Make sure to read this concise review of the bulletin and other patches released today.

Most people don't know but we offer patches here at Port80 as well (www.port80software.com/support/patches), though ours do not come with as much documentation and industry bombast.  However, they do save you an uninstall/reinstall.

Finally, a random aside on spyware: have you tried MS's new antispyware tool, beta version (http://www.microsoft.com/athome/security/spyware/software/default.mspx)? I have run Adaware and a few others, but this one somehow felt safer coming from MS. The tool is a breeze to install and found 3 hacks in less than five minutes -- one of them a browser helper object or BHO; very little “help" there... The tool should merge with windows update/firewall/outlook/exchange etc.

Cheers,
Port80

posted on Tuesday, January 11, 2005 6:07 PM

Feedback

# re: First IIS patch of '05 and Helpful, Courteous Spyware

More on the indexing patch from BindView:

"The Indexing Service is a fast, popular tool for searching file systems on Windows computers and by default is not enabled. A vulnerability in the query validation code of this service could allow for remote code execution. Microsoft Internet Information Services (IIS) Web servers are also vulnerable if the Indexing Service has been configured for the Web space, and if a web-based program has been provided to use the Indexing Service. Microsoft platforms affected by this new vulnerability include Windows 2000, Windows XP and Windows Server 2003."
1/13/2005 10:41 AM | IISDude@hotmail.com

Post Comment

Title:  
Name:  
Url:  
Comment:  
Verify:
(Enter the word as it appears in the box above.)