Silicon Shecky

Infosec Practitioner

  • About
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Links
    • Infosec
      • Burbsec
      • Infosec Exchange Mastodon
      • Hacks4Pancakes Blog
      • Krebs On Security
      • Bleeping Computer
  • Archives

Connect

  • Bluesky
  • LinkedIn
  • Mastodon
  • RSS
  • Twitter

[footer_backtotop]

Copyright © 2025 ·Sixteen Nine Pro Theme · Genesis Framework by StudioPress · WordPress

IIS 6.0 Flaw is serious

May 19, 2009 By Michael Kavka Leave a Comment

A new flaw in Microsoft’s IIS web server software has popped up, and this one is serious. It affects version 6 of IIS and while you do need to have WebDAV turned on and running, it can allow an attacker to completely compromise data on the server.

Threatpost has a very good description of it here.

The sad things about this is first Microsoft has no patch for it, heck they haven’t even confirmed it yet (they are still looking into it). Secondly, there was a similar vulnerability in an earlier version of IIS.

Right now the best bet is to turn off WebDAV if possible, or better yet uninstall it through add/remove programs and Windows Components (it is a sub component of IIS). Figure that you will see a patch for it somewhat soon.

Filed Under: Computers, Internet/Music, Security Tagged With: IIS 6.0, Microsoft, Security Holes, Security Patches, Threatpost, Web Sites, WebDAV

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

RSS Taggart Institute Intel Feed

  • Cybersecurity Reading List - Week of 2025-10-27 October 27, 2025 Ian Campbell
  • Conduent says data breach originally began with 2024 intrusion October 27, 2025 David Jones
  • US declines to join more than 70 countries in signing UN cybercrime treaty October 27, 2025
  • Google disputes false claims of massive Gmail data breach October 27, 2025 Lawrence Abrams
  • Attackers bypass patch in deprecated Windows Server update tool October 27, 2025 Matt Kapko
  • Microsoft WSUS Remote Code Execution (CVE-2025-59287) Actively Exploited in the Wild October 27, 2025 Unit 42
  • X: Re-enroll 2FA security keys by November 10 or get locked out October 27, 2025 Lawrence Abrams
  • Ransomware profits drop as victims stop paying hackers October 27, 2025 Bill Toulas
  • Sweden’s power grid operator confirms data breach claimed by ransomware gang October 27, 2025
  • 'House of Dynamite' Is About the Zoom Call that Ends the World October 27, 2025 Matthew Gault

Browse by tags

Active Directory Android Antivirus Apple Beta Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches Rants SBS SBS 2008 Security Security Patches Server SMB Software Support Surface TechEd Tweets Ubuntu Verizon Virus Vista vulnerabilities Windows Windows 7 Windows 8 XP