Silicon Shecky

Infosec Practitioner

  • About
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Links
    • Infosec
      • Burbsec
      • Infosec Exchange Mastodon
      • Hacks4Pancakes Blog
      • Krebs On Security
      • Bleeping Computer
  • Archives

Connect

  • Bluesky
  • LinkedIn
  • Mastodon
  • RSS
  • Twitter

[footer_backtotop]

Copyright © 2025 ·Sixteen Nine Pro Theme · Genesis Framework by StudioPress · WordPress

IIS 6.0 Flaw is serious

May 19, 2009 By Michael Kavka Leave a Comment

A new flaw in Microsoft’s IIS web server software has popped up, and this one is serious. It affects version 6 of IIS and while you do need to have WebDAV turned on and running, it can allow an attacker to completely compromise data on the server.

Threatpost has a very good description of it here.

The sad things about this is first Microsoft has no patch for it, heck they haven’t even confirmed it yet (they are still looking into it). Secondly, there was a similar vulnerability in an earlier version of IIS.

Right now the best bet is to turn off WebDAV if possible, or better yet uninstall it through add/remove programs and Windows Components (it is a sub component of IIS). Figure that you will see a patch for it somewhat soon.

Filed Under: Computers, Internet/Music, Security Tagged With: IIS 6.0, Microsoft, Security Holes, Security Patches, Threatpost, Web Sites, WebDAV

  • « Previous Page
  • 1
  • 2

RSS Taggart Institute Intel Feed

  • University of Sydney suffers data breach exposing student and staff info December 18, 2025 Bill Toulas
  • Clop ransomware targets Gladinet CentreStack in data theft attacks December 18, 2025 Sergiu Gatlan
  • Your car’s web browser may be on the road to cyber ruin December 18, 2025 Thomas Claburn
  • I am not a robot: ClickFix used to deploy StealC and Qilin December 18, 2025 Mindi McDowell
  • Adios 2025, you won’t be missed December 18, 2025 Joe Marshall
  • Crypto crooks co-opt stolen AWS creds to mine coins December 18, 2025 Jessica Lyons
  • Over $3.4 billion in crypto stolen throughout 2025, with North Korea again the top culprit December 18, 2025
  • The Curious Case of the Comburglar December 18, 2025 BHIS
  • Kim's crypto thieving reached a record $2B in 2025 December 18, 2025 Connor Jones
  • U.S. Sentencing Commission seeks input on criminal penalties for deepfakes December 18, 2025 djohnson

Browse by tags

Active Directory Android Antivirus Apple Beta Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches Rants SBS SBS 2008 Security Security Patches Server SMB Software Support Surface TechEd Tweets Ubuntu Verizon Virus Vista vulnerabilities Windows Windows 7 Windows 8 XP