Semicolon Bug Reveals IIS Vulnerability
A zero-day vulnerability in IIS revealed on Christmas day allows attackers to bypass file extension protections using a semicolon after an executable extension.
| ||||||||||||||||||||||
A zero-day vulnerability in IIS revealed on Christmas day allows attackers to bypass file extension protections using a semicolon after an executable extension.
Our series on Internet Information Server 6.0 on Windows Server 2003 kicks off with an overview of the underlying operating system that explains some of the differences between versions and how they impact IIS 6.0. We also offer an accompanying article for a quick refresher on Windows file system options.
Read Entire Review