Er zit weer eens een 'foutje' in de webserver van ome Bill. Zoals we van Mickrosoftware gewend zijn niet een klein foutje, maar meteen een vette security bug. Hier is de fun, afkomstig van ZDNet:
A security problem involving Microsoft Corp.'s Internet Information Server (IIS) and Site Server products leaves data and files stored on those products vulnerable to hackers, according to WebTrends Corp., an Internet reporting and management vendor.Three sample Active Server Pages (ASP) tools which ship as part of IIS and Site Server are the culprits, according to Microsoft (Nadaq:MSFT) and WebTrends. The default configurations of IIS and Site Server install the showcode.asp, viewcode.asp and codebrws.asp pages without proper access-control settings.
Any remote browser user who has read permissions and knowledge of file names on a given system can get at data and files on a given system via the ASP tools.