Android Century
  • Home
  • Android Zone
    • Android Apps
    • Android Games
    • Apps APk Files
    • Games Apk Files
    • Apps Hack Tricks
  • Reviews
  • Fantasy Zone
    • Entertainment
    • Quotes and Status
    • Life Style
    • Home Made Tips
    • Hair Care
    • Skin Care
    • Fantasy Tips
  • Tricks
    • Free Recharge
    • Free Internet
    • shopping Cashback
    • Recharge Cashback
  • Tech
  • Mobiles
  • Gadgets
  • News
  • How To's
  • Software
Breaking
Loading...

Featured post

How to Take Great Photos With Apple's iPhone X

Recent Posts

Labels

  • Android Apk Files
  • Android Apps
  • Android Games
  • Apps Apk Files
  • Entertainment
  • Fantasy Tips
  • Gadgets
  • Hair Care
  • HomeMade Tips
  • How To's
  • News
  • Quotes
  • Quotes & Status
  • Recharge Cashback
  • Recharge Promo Codes
  • Shopping Cashback
  • Technology
  • skin care
Home / News / Millions of web sites affected by unpatched flaw in Microsoft IIS 6 web server

Millions of web sites affected by unpatched flaw in Microsoft IIS 6 web server

Latest Govt. Jobs 21:49:00 News Edit
IIS 6.0 exploit could affect millions of websites.

A proof-of-concept exploit has been published for an unpatched vulnerability in Microsoft Internet Information Services 6.0, a version of the web server that’s no longer supported but still widely used.
The exploit allows attackers to execute malicious code on Windows servers running IIS 6.0 with the privileges of the user running the application. Extended support for this version of IIS ended in July 2015 along with support for its parent product, Windows Server 2003.
Even so, independent web server surveys suggest that IIS 6.0 still powers millions of public websites. In addition, many companies might still run web applications on Windows Server 2003 and IIS 6.0 inside their corporate networks, so this vulnerability could help attackers perform lateral movement if they access such networks through other means.
There’s evidence that this IIS vulnerability has been known by a limited number of attackers since at least July or August of last year. However, the publishing earlier this week of an exploit for it on GitHub makes it accessible to a larger number of hackers.
“Other threat actors are now in the stages of creating malicious code based on the original proof-of-concept (PoC) code,” researchers from Trend Micro said in a blog post Wednesday.
According to the exploit’s authors, the vulnerability is a buffer overflow in the ScStoragePathFromUrl function of the IIS 6.0 WebDAV service. It can be exploited through a specially crafted PROPFIND request.
Web Distributed Authoring and Versioning (WebDAV) is an extension of the standard Hypertext Transfer Protocol (HTTP) that allows users to create, change and move documents on a server. The extension supports several request methods, including PROPFIND, which is used to retrieve the properties of a resource.
Since Microsoft won’t patch this vulnerability, one possible mitigation is to disable the WebDAV service on IIS 6.0 installations. Security firm ACROS Security has also developed a free “micropatch” for this vulnerability—an unofficial patch that can be applied without restarting the affected server or even IIS process.
However, the best course of action would be to migrate affected websites to a newer IIS and Windows Server version altogether, as there are probably other vulnerabilities out there that also affect this platform and won’t get patched.
A March survey by web analytics firm Netcraft revealed that around 185 million websites are still hosted on over 300,000 web servers that run Windows Server 2003.
Share on Facebook Share on Twitter Share on Google Plus

RELATED POSTS


Xiaomi Redmi 5 with 18:9 display

Vivo V9 with dual rear cameras

Xiaomi Redmi 5 launch
Millions of web sites affected by unpatched flaw in Microsoft IIS 6 web server Millions of web sites affected by unpatched flaw in Microsoft IIS 6 web server Reviewed by Latest Govt. Jobs on 21:49:00 Rating: 5

0 comments:

Post a Comment

Newer Post Older Post Home
Subscribe to: Post Comments ( Atom )

Search This Blog

TEST BOOK FOR GOVT ENTRANCE TEST

TEST BOOK FOR GOVT ENTRANCE TEST
Find All Latest book for preparation of SSC,RAILWAYBANK PO,RBI,BANK CLERK,GATE ME,GATE CE are available here in less prices, to check out the books click here

Translate

  • Popular Post
  • Random posts
  • Category

Popular Posts

  • Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Refer & Earn Offer:  Hey Guys! Today I make an article about Teen Patti Referral ...
  • 11 things you should understand approximately iOS 11
    Apple introduced the following version of its running system for the iPhone and iPad, iOS eleven ...
  • KingRoot 4.8.1 (136) APK Latest Version Download
    Download KingRoot Latest Version 4.8.1 In Tools by Developer KingRoot Studio ( 4.x / 5  average ...
  • How to Disable Your Mac’s Touchpad When Another Mouse Is Connected
    Laptop trackpads can be annoying. Your palm hits them while you’re typing, moving your cursor ...
  • How to Gain Root Access of An Android Device via KingoRoot Software
    What Does Root Access Mean? Gaining root access of Android is the process of modifying the ...
  • Researchers trick 'CEO' email scammer into giving up identity
    Businesses targeted in email scams don’t always have to play the victim. They can actually ...

Random Posts

  • Crownit expands its services to 6 new cities
    Crownit expands its services to 6 new cities
    16.02.2017 - 0 Comments
    Crownit, the leading merchant discovery and privileges platform application, has announced the…
  • Mobikwik GET20 – Get 20% Cashback On Rs 50 Recharge & Bills Payment
    Mobikwik GET20 – Get 20% Cashback On Rs 50 Recharge & Bills Payment
    10.03.2016 - 0 Comments
    Mobikwik has come up with a new offer. Now get 20% cashback on Rs 50 recharge and bills payment. This is an…
  • Asus ROG Strix Hero edition review
    Asus ROG Strix Hero edition review
    22.01.2018 - 0 Comments
    While top-end gaming laptops have always been creme de la creme, the budget laptops have left people wanting…
  • Pandora's new top rate streaming service leans on personal playlists to compete with Spotify
    Pandora's new top rate streaming service leans on personal playlists to compete with Spotify
    13.03.2017 - 0 Comments
    After what feels like an eternity of teases and rumors, Pandora is finally ready to take the wraps off…
  • 08.03.2016 - 0 Comments
    Turning grey can make you look dapper but certainly not at 25! Even a streak of white at this age is…

Labels

Android Apk Files Android Apps Android Games Apps Apk Files Apps Hack Tricks Entertainment Free Internet Freecharge Gadgets Games Apk Files How To's Laptops Guide Mobiles Reviews Technology Viral's android zone free recharge

Entertainment

Tricks

Popular Posts

  • Infocus Vision 3 review
    What happens when ...
  • Researchers trick 'CEO' email scammer into giving up identity
    Businesses ...
  • How to Gain Root Access of An Android Device via KingoRoot Software
    What Does Root ...
  • How to Disable Your Mac’s Touchpad When Another Mouse Is Connected
    Laptop ...
  • Tinyowl Freecharge Offer – Get 15% Cashback + extra 25% cashback using Freecharge [Ultimatez Tricks]
    Tinyowl Freecharge ...
  • EVGA redesigns its graphics cards following overheating concerns
    Following a ...
  • (no title)
    ...

Random Posts

  • Clash Royale 1.2.3 (28) APK Latest Version Download [GoAndroidAuthority.Com]
    Clash Royale 1.2.3 (28) APK Latest Version Download [GoAndroidAuthority.Com]
    24.03.2016 - 0 Comments
    In Strategy by Top Developer Supercell(4.6/5 average rating on Google Play…
  • How to Create AdSense Account free
    How to Create AdSense Account free
    10.04.2017 - 0 Comments
    As a blogger, you have got truly heard of the AdSense software from Google which is appeared as one of the…
  • Xiaomi Redmi 5A available at discount in Big Bazaar sale
    Xiaomi Redmi 5A available at discount in Big Bazaar sale
    27.01.2018 - 0 Comments
    NEW DELHI: If you are planning to buy an entry level smartphone then you can consider going for the…
  • ‘Focused inbox’ feature being tested in the Windows 10 Mail app
    ‘Focused inbox’ feature being tested in the Windows 10 Mail app
    14.02.2017 - 0 Comments
    Although many of the features that will come to Windows 10 Creators Update have already reached the…
  • FCC head reportedly outlines plans to undo internet neutrality rules
    FCC head reportedly outlines plans to undo internet neutrality rules
    08.04.2017 - 0 Comments
    Federal Communications Commission Chairman Ajit Pai has disclosed preliminary plans to roll back some of…

Most Popular

  • Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Refer & ...
  • SAMSUNG GALAXY J7 (2016) REVIEWS
    SAMSUNG GALAXY J7 (2016) REVIEWS
    SAMSUNG GALAXY J ...
  • Top 5 Best SmartPhones under 7000 Rs (March 2017)
    Looking for the ...
  • Apple, IBM, Cisco are huge because of Indians, do not deny them H-1B visa: RBI Governor Urjit Patel
    ...
  • SAMSUNG GALAXY J7 (2016) Specifications
    SAMSUNG GALAXY J ...
  • BlackBerry Teases Marshmallow Beta Testing for Priv by Next Week
    Blackberry ...
  • LG Q6 Review
    LG Q6 Review
    2017 is ...

Contact Form

Name

Email *

Message *

Offers Zone

Created By Android Century Distributed by Android Century
  • Home
  • About us
  • Contact us
  • Privacy policy
  • Terms of use
  • Advertise here
Subscribe Via Email Subscribe To Android Century By Email And Get Free Updates. ;-)


Your email address is safe with us!