| |
|
Wednesday, April 10, 2002
|
|
Unsafe at any speed
The security office at the university where I work uses a third-party security scanning program to automatically check out our machines for vulnerabilities. The latest version hit a machine I am working with (.NET Server Beta 3 with IIS 6.0) and reported a "medium-risk vulnerability"--the presence of IIS. This is something new; always before, the vulnerabilities were specific and the fixes were concise: change this registry entry, disable this account, reset these privileges. But here the remedy is more extreme: remove IIS.
9:46:02 AM
|
|
|
© Copyright 2003 Jim Klopfenstein.
Last update: 3/14/2003; 11:41:26 AM.
|
|
|