Silicon Shecky

Infosec Practitioner

  • About
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Links
    • Infosec
      • Burbsec
      • Infosec Exchange Mastodon
      • Hacks4Pancakes Blog
      • Krebs On Security
      • Bleeping Computer
  • Archives

Connect

  • Bluesky
  • LinkedIn
  • Mastodon
  • RSS
  • Twitter

[footer_backtotop]

Copyright © 2025 ·Sixteen Nine Pro Theme · Genesis Framework by StudioPress · WordPress

IIS 6.0 Flaw is serious

May 19, 2009 By Michael Kavka Leave a Comment

A new flaw in Microsoft’s IIS web server software has popped up, and this one is serious. It affects version 6 of IIS and while you do need to have WebDAV turned on and running, it can allow an attacker to completely compromise data on the server.

Threatpost has a very good description of it here.

The sad things about this is first Microsoft has no patch for it, heck they haven’t even confirmed it yet (they are still looking into it). Secondly, there was a similar vulnerability in an earlier version of IIS.

Right now the best bet is to turn off WebDAV if possible, or better yet uninstall it through add/remove programs and Windows Components (it is a sub component of IIS). Figure that you will see a patch for it somewhat soon.

Filed Under: Computers, Internet/Music, Security Tagged With: IIS 6.0, Microsoft, Security Holes, Security Patches, Threatpost, Web Sites, WebDAV

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

RSS Taggart Institute Intel Feed

  • Chatbots parrot Putin's propaganda about the illegal invasion of Ukraine October 28, 2025 Thomas Claburn
  • Cybersecurity Awareness Month: 4 reasons CISOs make exposure management a cornerstone of their cybersecurity strategy October 28, 2025
  • Marks & Spencer swaps out TCS for fresh helpdesk deal October 28, 2025 Lindsay Clark
  • Toward a Taiwan Truce October 28, 2025 Stephen Wertheim
  • Talking about “Kavanaugh stops” with law prof Anil Kalhan, who coined the term October 28, 2025 Chris Geidner
  • ISC Stormcast For Tuesday, October 28th, 2025 https://isc.sans.edu/podcastdetail/9674, (Tue, Oct 28th) October 28, 2025
  • WSUS attacks hit 'multiple' orgs as Google and other infosec sleuths ring Redmond’s alarm bell October 27, 2025 Jessica Lyons
  • Cybersecurity Reading List - Week of 2025-10-27 October 27, 2025 Ian Campbell
  • Conduent says data breach originally began with 2024 intrusion October 27, 2025 David Jones
  • US declines to join more than 70 countries in signing UN cybercrime treaty October 27, 2025

Browse by tags

Active Directory Android Antivirus Apple Beta Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches Rants SBS SBS 2008 Security Security Patches Server SMB Software Support Surface TechEd Tweets Ubuntu Verizon Virus Vista vulnerabilities Windows Windows 7 Windows 8 XP