Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Remote Code Execution Via HTTP Request In IIS On Windows
Mattias website ^ | Wednesday, April 15, 2015 | Mattias Geniar

Posted on 04/15/2015 7:33:51 PM PDT by Utilizer

A remote code execution vulnerability exists in the HTTP protocol stack (HTTP.sys) that is caused when HTTP.sys improperly parses specially crafted HTTP requests. An attacker who successfully exploited this vulnerability could execute arbitrary code in the context of the System account.

To exploit this vulnerability, an attacker would have to send a specially crafted HTTP request to the affected system. The update addresses the vulnerability by modifying how the Windows HTTP stack handles requests.

(Excerpt) Read more at ma.ttias.be ...


TOPICS: Computers/Internet
KEYWORDS: http; microsoft; mswindows; security; windows; windowspinglist
Navigation: use the links below to view more comments.
first previous 1-2021-31 last
To: Windflier
My Win7 computer ate 16 updates from MS today. Took forever, too! Is it possible this patch was included?
It was likely included. If you run Windows Update, you can check the list of installed updates. The update you want is KB3042553. If it is not, you can download the update separately, if you want. Here is a list of links for various Windows versions.
21 posted on 04/16/2015 1:20:24 AM PDT by cartan
[ Post Reply | Private Reply | To 20 | View Replies]

To: Utilizer
According to Netcraft, https://mail.clintonemail.com/ is running Microsoft-IIS/7.5.

Must be secure, since it's alleged to be under USSS protection! But, really, what difference does it make?

22 posted on 04/16/2015 1:31:37 AM PDT by cynwoody
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer; bicyclerepair
I think you posted on the wrong thread, mate.

Nope, BCR got it right, although you don't actually need the Mint version to host a web site. The server version will do just fine.

The key is, anyone with a half a brain knows, Linux is the OS to use if you want to serve websites.

23 posted on 04/16/2015 1:36:17 AM PDT by cynwoody
[ Post Reply | Private Reply | To 16 | View Replies]

To: cynwoody
The key is, anyone with a half a brain knows, Linux is the OS to use if you want to serve websites.

Yeah, well, good luck with that if your enterprise requires the use of Microsoft Exchange Server, Active Directory Certificate Services, or SharePoint Server...

All REQUIRE IIS to use their full functionality.

Sometimes a system admin needs to know how to lock down/secure what he has been given to work with... Installing Linux is not an option for those roles.

24 posted on 04/16/2015 3:38:00 AM PDT by Alas Babylon! (As we say in the Air Force, "You know you're over the target when you start getting flak!")
[ Post Reply | Private Reply | To 23 | View Replies]

To: Alas Babylon!
Yeah, well, good luck with that if your enterprise requires the use of Microsoft Exchange Server, Active Directory Certificate Services, or SharePoint Server...

Ick. Don't need that crap!

The goal should always be to streamline the enterprise and cut out the dead wood. Boosts productivity!

25 posted on 04/16/2015 3:53:57 AM PDT by cynwoody
[ Post Reply | Private Reply | To 24 | View Replies]

To: cynwoody

And in a 200 person IT department filled with policies, procedures, change management protocols and a executive staff wined and dined by vendors you’re going to get them to accept your idea of what’s crap or not?

Reality is a bee-otch. I don’t think you work in IT.


26 posted on 04/16/2015 4:17:33 AM PDT by Alas Babylon! (As we say in the Air Force, "You know you're over the target when you start getting flak!")
[ Post Reply | Private Reply | To 25 | View Replies]

To: dayglored

Well, I got a notice yesterday, that I have 14 critical updates - but after what I’ve been through the past two weeks, I’m not so sure I want to do this.

So, I’m asking what this newest set of updates are all about and what are my risks ..??

thanks


27 posted on 04/16/2015 7:41:10 AM PDT by CyberAnt ("The hour has arrived to gather the Harvest")
[ Post Reply | Private Reply | To 12 | View Replies]

To: dayglored

Thanks for the ping.


28 posted on 04/16/2015 8:18:43 AM PDT by GOPJ (Hillary Candidacy Like "Weekend At Bernie's" they'll have to keep proppering her up - H.Hewitt)
[ Post Reply | Private Reply | To 12 | View Replies]

To: Alas Babylon!
Reality is a bee-otch. I don’t think you work in IT.

Shhh... calm down Babs. You know he's probably management. When you work in the ivory tower, everything is as simple as "how much will it cost?"

29 posted on 04/16/2015 9:32:37 AM PDT by rarestia (It's time to water the Tree of Liberty.)
[ Post Reply | Private Reply | To 26 | View Replies]

To: Utilizer

BFL


30 posted on 04/16/2015 10:07:33 AM PDT by metesky (My investment program is holding steady @ $0.05 cents a can.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: bicyclerepair; ShadowAce
I love linux mint, best OS ever %u

I am glad for an alternatives to Windows, and run Xubuntu on a old laptop dual booting with XP, having tried every major and a few minor distros and found Xubuntu/Xfce the best for older HW.

However, it is only a supplement as i always find is lacking the degree of functionality I can easily achieve in Windows (thank God). Besides lacking legal codecs for certain media, sometimes it is the security which prevents me from dealing with my own files, or things like the ability to just right click on an icon in the application menu and find the location, or the lack of Windows equivalent software, or Wine to run the Win versions.

I just installed Xubuntu on a rig with a 2.8ghz cpu and 4 gb ram, but cannot find a easy reliable way to remap the Caps key to ctrl+c, and the Esc key to ctrl+v, and NumLock to Esc, which i do because of my arthritic fingers (Keyboard > Layouts does not do it). Using AutoHotKey this is easy in Windows. Or a app like Quick Paste. There are others, like PhoneTrayFree and T-Clock.

And downloading Dropbox took about 10 minutes, while in Windows it takes seconds. But thank God for Firefox and Apache or Libre Office, as i can migrate the user profiles from Windows.

31 posted on 04/17/2015 6:22:27 PM PDT by daniel1212 (Come to the Lord Jesus as a contrite damned+destitute sinner, trust Him to save you, then live 4 Him)
[ Post Reply | Private Reply | To 15 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-31 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson