![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.10695 |
Category: | Web Servers |
Title: | Microsoft IIS .IDA ISAPI Filter Applied - Active Check |
Summary: | Indexing Service filter is enabled on the remote Web server. |
Description: | Summary: Indexing Service filter is enabled on the remote Web server. Vulnerability Insight: The IIS server appears to have the .IDA ISAPI filter mapped. At least one remote vulnerability has been discovered for the .IDA (indexing service) filter. This is detailed in Microsoft Advisory MS01-033, and gives remote SYSTEM level access to the web server. It is recommended that even if you have patched this vulnerability that you unmap the .IDA extension, and any other unused ISAPI extensions if they are not required for the operation of your site. Solution: To unmap the .IDA extension: 1.Open Internet Services Manager. 2.Right-click the Web server choose Properties from the context menu. 3.Master Properties 4.Select WWW Service -> Edit -> HomeDirectory -> Configuration and remove the reference to .ida from the list. In addition, you may wish to download and install URLSCAN from the Microsoft Technet web site. URLSCAN, by default, blocks all .ida requests to the IIS server. CVSS Score: 10.0 CVSS Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2001-0500 BugTraq ID: 2880 http://www.securityfocus.com/bid/2880 Bugtraq: 20010618 All versions of Microsoft Internet Information Services, Remote buffer overflow (SYSTEM Level Access) (Google Search) http://www.securityfocus.com/archive/1/191873 http://www.cert.org/advisories/CA-2001-13.html Computer Incident Advisory Center Bulletin: L-098 http://www.ciac.org/ciac/bulletins/l-098.shtml Microsoft Security Bulletin: MS01-033 https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-033 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A197 http://www.iss.net/security_center/static/6705.php |
Copyright | Copyright (C) 2001 Matt Moore |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |