| Improperly Formatted HTTP Request May Cause INETINFO Process to FailID: Q234905 
 | 
When a Web site visitor requests a selected file mapping, the request is mapped to an appropriate DLL for processing the visitor's request. The appropriate DLL may include any Microsoft DLL or an installed third-party filter DLL. A problem currently exists in the Microsoft DLLs for handling an improperly formatted request that uses an HTR, STM, or IDC application mapping. There is the possibility that this problem could be exploited by a malicious Web user by sending an improperly formatted HTTP request to a Microsoft Internet Information Server (IIS) computer, which can result in the unstable operation of the Web server.
Microsoft has provided a patch to correct this problem; however, additional steps can be used to prevent issues similar to this one from impacting any Microsoft IIS 4.0 computer. Selecting Check if file Exists in the script application mappings section of the ISM forces IIS 4.0 to check if the requested script exists or if the user has permission to the requested script. If not, the appropriate warning message is returned to the browser and the script engine is not invoked.
To select Check if file Exists, perform the following steps:
A supported fix that corrects this problem is now available from Microsoft, but 
it has not been fully regression tested and should be applied only to systems 
experiencing this specific problem. If you are not severely affected by this 
specific problem, Microsoft recommends that you wait for the next Windows NT service pack 
that contains this fix.
To resolve this problem immediately, contact Microsoft Product Support Services 
to obtain the fix. For a complete list of Microsoft Product Support Services 
phone numbers and information on support costs, please go to the following 
address on the World Wide Web:
http://www.microsoft.com/support/supportnet/overview/overview.aspThe English version of this fix should have the following file attributes or later:
   Date       Time                Size    File name     Platform
   -------------------------------------------------------------
   06-09-1999 6:51:10PM           53,504  Ism.dll       x86
   06-09-1999 6:36:02PM           82,704  Ism.dll       Alpha ftp://ftp.microsoft.com/bussys/IIS/iis-public/fixes/usa/ext-fix/
Q154871 Determining If You Are Eligible for No-Charge Technical Support
Microsoft has confirmed this to be a problem in Internet Information Server 4.0.
The effected application mappings are IDC, HTR, and STM.
Patch Available for "Malformed HTR Request" VulnerabilityFor additional security-related information about Microsoft products, please visit:
http://www.microsoft.com/security
Additional query words:
Keywords          : 
Version           : winnt:4.0
Platform          : winnt 
Issue type        : kbbug Last Reviewed: July 2, 1999