bk99.de entertain the web since 1997

Security check for Microsoft’s Internet Information Server

Summary

In August 2000 the Czech magazine Svět Namodro provided a web form with which administrators could check Microsoft IIS servers for known holes. All the flaws checked in IIS 4.0 and 5.0 were known and, according to Microsoft, fixed with Service Pack 1 for Windows 2000. The security company iDefense nevertheless warned that attackers could use the tool to pre-select vulnerable targets.

Ideas

  • A public scanner helps defenders and attackers alike.
  • Known holes that had long been patched remained open on many servers.
  • The tool only checked known flaws, not new vulnerabilities.

Insights

  • The greatest risk often lies not in new holes but in updates that have not been installed.
  • Whether a testing tool does harm depends on who uses it first and against whom.

Facts

  • According to Svět Namodro, about half of the IIS sites tested had at least one security flaw.
  • IIS 4.0 and 5.0 were checked.

References

Critique

  • The report does not say whether the tool only checked the user’s own servers or accepted any address.

Remarks

  • A year later, the Code Red and Nimda worms spread through exactly such unpatched IIS servers.

Recommendations

  • Scan your own servers regularly for known vulnerabilities before others do.
  • Install service packs and security updates for publicly reachable services promptly.

Read the original article

Search the Web Archive