site Search:


 
    All Forums Hot Topics Gallery






how-to block ads


 
Search Topic:
Share Topic
Posting?
Post a:
Post a:
Links: ·Hijack This logs? ·Panda Free Tools ·Vundo Removal
AuthorAll Replies


KodiacZiller
Premium
join:2008-09-04
73368
kudos:2

reply to Smokey Bear

Re: Microsoft IIS 0-Day Vulnerability in Parsing Files

LOL. Just goes to show how silly the whole notion of file extensions (in relation to security) is.


djrobx

join:2000-05-31
Valencia, CA
kudos:1
Reviews:
·Verizon Wireless..
·RoadRunner Cable
·AT&T U-Verse
·VOIPo
·PHONE POWER

1 edit

said by KodiacZiller:

LOL. Just goes to show how silly the whole notion of file extensions (in relation to security) is.
Yeah, that's what I don't quite understand about this vulnerability. Why on earth would you allow users to upload to a folder with scripts/execute permissions enabled? The extension should be irrelevant.
--
AT&T U-Hearse
Your funeral. Delivered.


asdfghjklzx5
Premium
join:2004-05-03
kudos:1

said by djrobx:

said by KodiacZiller:

LOL. Just goes to show how silly the whole notion of file extensions (in relation to security) is.
Yeah, that's what I don't quite understand about this vulnerability. Why on earth would you allow users to upload to a folder with scripts/execute permissions enabled? The extension should be irrelevant.
Because most Windows server admins don't ever think about security. This vulnerability can't be exploited if proper permissions are set on the directory.
--
"Ubuntu protects you from malware in the same way that a Geo protects you from carjackers." -Anonymous


EGeezer
Summertime
Premium
join:2002-08-04
Midwest
kudos:7
Reviews:
·Callcentric

1 edit

said by asdfghjklzx5:

Because most Windows server admins don't ever think about security. This vulnerability can't be exploited if proper permissions are set on the directory.
I'd also add that there are actually software vendors out there today whose applications require administrative access to the entire C: drive of a server. I had one such setup. Later, they tried to tell us we also had to open up ports to allow Dameware for them to provide support. We told them that if they couldn't live with a secured connection and a completely firewalled network, we'd get another vendor. They finally screwed up enough we dropped them anyhow.
--
The greatest dangers to liberty lurk in insidious encroachment by men of zeal, well-meaning but without understanding. -- Justice Louis D. Brandeis

Sunday, 03-Jun 08:51:25 Terms of Use & Privacy | feedback | contact | Hosting by nac.net - DSL,Hosting & Co-lo
over 12.5 years online © 1999-2012 dslreports.com.
Most commented news this week
Hot Topics