[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <BAY10-DAV138500ADD922A4ACC8EDA7D9730@phx.gbl>
From: se_cur_ity at hotmail.com (morning_wood)
Subject: re: Microsoft Outlook Web Access URL Injection
looks like MS is NOT publicly releasing a fix for this, while they have the
means and solution at hand.
( at least under IE )
a kind reader sent this little snippet...
"... was able to get Microsoft to provide us with a DLL
to drop under IIS 6 to compare URL variable against the Host: header
variable and do 302 to web root if they are not similar. This fixed the
problem, however, I doubt that Microsoft will make this patch available to
the public."
what happend to MS commitment to security???
ugg,
m.w
Powered by blists - more mailing lists