Peaches Posted December 29, 2009 Report Share Posted December 29, 2009 28 December 2009, 10:17Security flaw in Microsoft IIS Soroush Dalili has discovered that various versions of Microsoft's Internet Information Services (IIS) contain a security flaw that can be exploited to inject and execute malicious code on Windows web servers. Dalili writes that the problem occurs during the parsing of filenames with a semicolon extension in IIS. When ";.jpg" is added to an .asp file, for instance, systems that merely analyze the executability of code based on the ultimate file ending can be duped; a file entitled "malicious.asp;.jpg" would then be executed as an .asp file. More at Heise security - http://www.h-online....IIS-892881.html Quote Link to post Share on other sites
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.