What are the known security of IIS with WebDav??
Web Server forum
Back To The Forum Home!Search!Private Messaging System

Web Server Talk Web Server Talk > Web Servers reviews > IIS server support > IIS Server Security > What are the known security of IIS with WebDav??




  Last Thread   Next Thread Next
  Show Printable Version Email this Page Subscribe to this Thread      Post New Thread    Post A Reply      

    What are the known security of IIS with WebDav??  
WilliamVeldhuizen.@.somewhere.com


View Ip Address Report This Message To A Moderator Edit/Delete Message


 
07-17-07 06:21 PM

We have plans for implement WebDav in our Web-application and
therefore i am searching some information about WebDav on the IIS
platform.

Our internet hosting provider tells about some security problems with
WebDav and they are wary for hosting WebDav. Unfortunately, they can't
tell me the exact problems.

Does anyone knowns security issues/problems of IIS (6.0 or 7.0) with
WebDav?





[ Post a follow-up to this message ]



    Re: What are the known security of IIS with WebDav??  
David Wang


View Ip Address Report This Message To A Moderator Edit/Delete Message


 
07-18-07 06:22 AM

On Jul 17, 5:44 am, WilliamVeldhuizen.@.somewhere.com wrote:
> We have plans for implement WebDav in our Web-application and
> therefore i am searching some information about WebDav on the IIS
> platform.
>
> Our internet hosting provider tells about some security problems with
> WebDav and they are wary for hosting WebDav. Unfortunately, they can't
> tell me the exact problems.
>
> Does anyone knowns security issues/problems of IIS (6.0 or 7.0) with
> WebDav?



IIS7 does not (yet) have WebDAV support. It is being completely
rewritten for IIS7 because of underlying architectural changes.

To date, there is one known security issue involving WebDAV and IIS6.
However, it is hardly a security issue/problem of IIS6 because it is
actually a vulnerability within MSXML, which happens to be used by
WebDAV and exposed to the Internet via IIS. Sure, it is a
"vulnerability involving IIS", but it is hardly unique to IIS (i.e.
you can exploit it in any other way that MSXML gets invoked).

Personally, I think your internet hosting provider just doesn't want
to do any work to support you and is randomly blaming it on
"security". Since its release in 2003, IIS6 has proven to be highly
secure. One can count the number of IIS6 related security issues with
a few fingers on one hand (for example, see: http://secunia.com/product/1438/?ta.../>
=statistics
), and the issues are relatively minor:
- cookie mishandling of = - return ASP error page detailing ASP file
location
- WebDAV exposure of MSXML - Denial of service by MSXML
- ASP buffer overflow -- which sounds bad until one realizes that IIS
runs ASP with an unprivileged process identity.


//David
http://w3-4u.blogspot.com
http://blogs.msdn.com/David.Wang
//






[ Post a follow-up to this message ]



    Sponsored Links  




 





   All times are GMT. The time now is 09:50 AM.      Post New Thread    Post A Reply      
  Last Thread   Next Thread Next


Most Popular forums 

Forum Jump:
Rate This Thread:

Forum Rules:
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is OFF
vB code is ON
Smilies are ON
[IMG] code is OFF
 
Medical and Health forum | Computer Games Reviews | Graphics design forum

Back To The Top
Home | Usercp | Faq | Register