Bink.nu Services

Subscribe to our feed 

 


Order Now!

Windows 7 for XP Professionals
Updating Support Skills from XP to Windows 7
by Bink.nu's Raymond Comvalius

Who is online

There are 60 guest(s) online.

There are 0 member(s) online.

Sponsors



Archives

Posted by Steven Bink September 25, 2010 11:36 AM with no comments

The Microsoft Security Response Center (MSRC): We've updated Microsoft Security Advisory 2416728 to include a step in the workaround requiring the blocking of requests that specify the application error path on the querystring.  This can be done using URLScan, a free tool for Internet Information Services (IIS) that can selectively block requests based on rules defined by the administrator. If your system is running Internet Information Services (IIS) on Windows Vista Service Pack 2, Windows Server 2008 Service Pack 2, Windows 7, or Windows Server 2008 R2, you can alternatively use the Request Filtering feature.

If you've already implemented the workaround we've previously published, please add this additional step to help block attackers from exploiting the vulnerability.

Microsoft remains committed to taking the appropriate action to help protect our customers. Through our comprehensive monitoring, we continue to see limited active attacks. We want to assure you that we have teams working around the clock worldwide to develop a security update of appropriate quality for distribution to address this vulnerability.  For additional information on the updated workaround, visit Scott Guthrie's blog.

The Security Advisory will be updated with any new developments so if you are not already subscribed to our comprehensive alerts, please do so in order to be alerted by email when new information is added. Sign up here: http://technet.microsoft.com/en-us/security/dd252948.aspx

We will also keep customers apprised of any additional details and updates through the MSRC Blog.

108352 Views

Comments

No Comments

About Steven Bink

Founder of Bink.nu
Bink.nu 3.0. Copyright © 1999-2012 Steven Bink. All Rights Reserved.
Microsoft and Microsoft logo's are trademarks of Microsoft Corporation.