lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Fri, 18 Apr 2014 15:15:43 -0500
From: Homer Parker <hparker@...ershut.net>
To: fulldisclosure@...lists.org
Subject: Re: [FD] iis cgi 0day

On Wed, 2014-04-16 at 12:25 +0200, Reindl Harald wrote:
> Am 16.04.2014 08:39, schrieb Davide Davini:
> > YiFei Yang wrote:
> >> It is a bug affecting IIS4/5 using CGI on Windows NT/2000. Microsoft is
> >> aware of it and won't fix it.
> > 
> > Is there any workaround this bug? I might be slow but I can't find any
> 
> just don't use unsupported OS versions if you care about
> security - i know people even forgot NT/2000 existed

	Oh?

<http://news.netcraft.com/archives/2014/04/08/thousands-of-websites-still-hosted-on-windows-xp.html>

-- 
Homer Parker <hparker@...ershut.net>

Download attachment "signature.asc" of type "application/pgp-signature" (199 bytes)


_______________________________________________
Sent through the Full Disclosure mailing list
http://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: http://seclists.org/fulldisclosure/

Powered by blists - more mailing lists