Patch it now! (MS HTTP bug)

Patch it now! (MS HTTP bug)

1 This isn't an IIS bug, so it doesn't apply only to IIS servers.

As far as we can see, the bug affects pretty much any Windows software that uses Microsoft's HTTP stack to respond to HTTP requests, whether that software runs on desktops, laptops or servers.

All sorts of software could fall into that category: custom company messaging systems; data loggers; configuration agents; peer-to peer-tools; heck, even an existing malware infection!

2 The bug allows remote code execution.

3 The bug can be triggered with an innocent-looking HTTP request from outside your network.

That means that the bug could, in theory, be turned into a true network worm like the Morris Internet Worm or SQL Slammer.

Those worms spread without having to wait for users to do anything such as clicking a web link or opening an attachment.

4 The bug is in a kernel component, and a successful exploit gives the attacker SYSTEM privileges.

As explained above, that is as good as taking over your computer entirely.

5 Even Server Core is affected.

6 Proof of Concept (PoC) exploit code can already be found on the internet.

The proof of concept we've seen doesn't actively attempt to exploit the bug and do anything deliberately malicious.

But reports say that a probe by the PoC does actually trigger a buffer overflow, which could be distracting and time-consuming when you review your logs.

(You do review your logs regularly. Don't you?)

Special mitigation for IIS

If you have an IIS server, you can shield it from harm even before you apply the M15-034 update, using a workaround published by Microsoft:

Disable IIS kernel caching.

Note that kernel caching is enabled by default in IIS 7 and later.

Source: Sophos Security News

http://tinyurl.com/n4tv5xz

 

To view or add a comment, sign in

More articles by James King

  • Disconnect!

    Ensure that when you work hard, you play hard. Somewhere in between, disconnect and get that much needed downtime.

    3 Comments
  • Compliance Engine beta-launch

    Multi-project, multi-jurisdiction white-label crowdfunding platform!

    2 Comments
  • The Dangers of online password vaults

    I've been warning for years that if you're going to use an APP or service to manage your accounts or passwords, you…

    10 Comments
  • DDos Attacks

    Distributed Denial of Service (DDoS)1 attacks against the Web sites of State, Local, Territorial, and Tribal…

    2 Comments
  • USB Devices!

    I've been stating and teaching this for years. Why do organizations continue to allow USB / data access on their…

  • Microsoft FREAK!

    Action Required: If you run a server … You should immediately disable support for TLS export cipher suites. While…

  • I love Utah!

    So often I am asked: "Why do you live and stay in Utah"? My answer is simple. Where else in America can you be up at…

    9 Comments
  • Go-Go in flight serving up bogus SSL Certs!

    This specific bulletin really saddens me as I have been an active subscriber to this service. Again, as many are…

    3 Comments
  • Utah Business Fast50

    MasterControl again named to the Utah Fast50 as the 36th fastest growing business in Utah! Congrats to the entire staff…

    5 Comments
  • MasterControl v11 has launched!

    http://mastercontrol.com/v11/ Sometimes accelerating your business means growing and expanding.

Others also viewed

Explore content categories