Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




Vulnerability Development mailing list archives

Re: CR II - winME? confirmation? (Slightly OT)
From: "Amer Karim" <amerk () telus net>
Date: Tue, 7 Aug 2001 08:03:33 -0700

Hi All,

All the advisories about CR state that only IIS servers are vulnerable.
However, it’s my understanding that the unchecked buffer in idq.dll was the
source of that vulnerability.  If that’s the case, then why have the
advisories not included Win2K systems (all flavours) since idq.dll is
installed by default as part of the indexing service on all these systems –
regardless of whether they are using the service or not?  Wouldn’t that make
ANY system with the indexing service on it just as vulnerable as systems
with IIS? Am I overlooking something obvious here?

Regards,
Amer Karim
Nautilis Information Systems
e-mail: amerk () telus net, mamerk () hotmail com



  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]