Solution Available for File Viewers Vulnerability

ID: Q231368


The information in this article applies to:


SYMPTOMS

Microsoft has identified a vulnerability that occurs in some file viewers that are included with Microsoft Site Server and Internet Information Server.

The vulnerability could allow a Web site visitor to view, but not to change, files on the server, provided that the visitor knows or guesses the name of each file and has access rights to the file based on the Windows NT Access Control Lists (ACLs).


CAUSE

The file viewer tools do not restrict which files a user can view.


RESOLUTION

Site Server 3.0 Fix

A fix has been developed for Site Server 3.0, and has been posted to the following Internet location as Viewfixi.exe (x86):
ftp://ftp.microsoft.com/bussys/sitesrv/sitesrv-public/fixes/usa/siteserver3/hotfixes-postsp2/Viewcode-fix/


NOTE: A version for Alpha platforms will be available shortly.

Please see the following article in the Microsoft Knowledge Base for more information about this fix:
Q231656 Preventing Viewcode.asp from Viewing Known Server Files

IIS 4.0 Fix

A fix has been developed for IIS 4.0, and has been posted to the following Internet location as Fix2450I.exe (Intel) or Fix2450A.exe (Alpha):
ftp://ftp.microsoft.com/bussys/iis/iis-public/fixes/usa/Viewcode-fix/

Please see the following article in the Microsoft Knowledge Base for more information about this fix:
Q232449 Sample ASP Code May be Used to View Unsecured Server Files


WORKAROUND

To eliminate the vulnerability on your Web server that can be caused by these file viewers, you should:


MORE INFORMATION

Microsoft Site Server and Internet Information Server (IIS) include tools that allow Web site visitors to view selected files on the server. These tools are installed by default in Site Server, but must be explicitly installed in IIS. These tools are provided to allow users to view the source code of sample files as a learning exercise, and are not intended to be deployed on production Web servers. The underlying problem in this vulnerability is that the tools do not restrict which files a Web site visitor can view.

Note the following important points:

Additional References

Additional query words: patch hotfix hot fix default setup set up viewcode utility hacker breach read see source cpa


Keywords          : 
Version           : winnt:2.0,3.0,4.0,4.5
Platform          : winnt 
Issue type        : kbprb 

Last Reviewed: June 2, 1999