New IIS vulnerabilities revealed
Early this morning a chinese firm named nsfocus announced a new IIS exploit. The exploit is caused by IIS decoding the URL twice, once accidentally decoding the path to the file you are accessing. A default installed IIS 4 or IIS 5 box will usually be vulnerable to this example:
http://TARGET/scripts/..%255c..%255cwinnt/system32/cmd.exe?/c+dir+c:
There are also 2 other less serious exploits that were released today, and are patched in the same release by MS. The other exploits were mostly DoS or ftp weaknesses, research more here:
IIS vulnerability: CAN-2001-0333
FTP denial of service vulnerability: CAN-2001-0334
FTP user account vulnerability: CAN-2001-0335
Denial of service vulnerability in MS00-060 patch: CAN-2001-0336
Memory leak in MS01-014 and MS01-016 patches: CAN-2001-0337
Microsoft's Technet Page for this patch
Microsoft has the patch all ready, and will also patch for every other vulnerability that has been discovered since NT4sp5 (for IIS4) or all patches released (for IIS5). This will come as a relief to many IIS administrators who worry they have missed one of those wonderful 'hotfixes'.