<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Systech Solutions LTD. &#187; WebDAV Request Vulnerability</title>
	<atom:link href="http://www.systechsolutions.info/blog/tag/webdav-request-vulnerability/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.systechsolutions.info/blog</link>
	<description>Making the most out of your technology.</description>
	<lastBuildDate>Wed, 21 Oct 2009 13:44:30 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>US-CERT Current Activity &#8211; Microsoft Internet Information	Services (IIS) WebDAV Request Vulnerability &#8211; MICROSOFT</title>
		<link>http://www.systechsolutions.info/blog/2009/05/us-cert-current-activity-microsoft-internet-informationservices-iis-webdav-request-vulnerability-microsoft/</link>
		<comments>http://www.systechsolutions.info/blog/2009/05/us-cert-current-activity-microsoft-internet-informationservices-iis-webdav-request-vulnerability-microsoft/#comments</comments>
		<pubDate>Mon, 18 May 2009 15:28:01 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Microsoft and US-Cert Security Bulletins]]></category>
		<category><![CDATA[WebDAV Request Vulnerability]]></category>

		<guid isPermaLink="false">http://www.systechsolutions.info/?p=553</guid>
		<description><![CDATA[The following US-Cert announcement pertains to IIS 6, which most commonly can be found running on Windows Server 2003, and Windows XP Professional x64 edition.


&#8220;US-CERT Current Activity
 
Microsoft Internet Information Services (IIS) WebDAV Request Vulnerability
 
Original release date: May 18, 2009 at 8:54 am Last revised: May 18, 2009 at 8:54 am


 
 
US-CERT is [...]]]></description>
			<content:encoded><![CDATA[<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;">The following US-Cert announcement pertains to IIS 6, which most commonly can be found running on Windows Server 2003, and Windows XP Professional x64 edition.</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;">
<blockquote>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;">&#8220;US-CERT Current Activity</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;">Microsoft Internet Information Services (IIS) WebDAV Request Vulnerability</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;">Original release date: May 18, 2009 at 8:54 am Last revised: May 18, 2009 at 8:54 am</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"><br />
</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;">US-CERT is aware of public reports of a vulnerability affecting Microsoft Internet Information Services 6 (IIS6). Reports indicate that this vulnerability is due to improper handling of unicode tokens.</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"><br />
</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;">Exploitation of this vulnerability may allow a remote attacker to bypass authentication methods, allowing an attacker to upload files to a WebDAV folder or obtain sensitive information. US-CERT is also aware of publicly available exploit code and active exploitation of this vulnerability.</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;">US-CERT encourages users to implement the following workaround to help mitigate the risks until a patch or update is available from the</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;">vendor: Disable WebDAV. Administrators who are unable to disable WebDAV may be able to mitigate some risk by configuring their IDS to refuse external HTTP requests containing &#8220;Translate: f&#8221; headers. Please note that disabling WebDAV may affect the functionality of other applications such as SharePoint.</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"><br />
</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;"> </span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;">US-CERT will provide additional information as it becomes available.</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;">====</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Consolas;">This entry is available at</span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"><a href="http://www.us-cert.gov/current/index.html#microsoft_internet_information_services_iis"><span style="font-size: small; font-family: Consolas;">http://www.us-cert.gov/current/index.html#microsoft_internet_information_services_iis</span></a>&#8220;</p>
</blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.systechsolutions.info/blog/2009/05/us-cert-current-activity-microsoft-internet-informationservices-iis-webdav-request-vulnerability-microsoft/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
