[2750] in WWW Security List Archive
RE: Intranet branch security
daemon@ATHENA.MIT.EDU (Paul Leach)
Wed Aug 21 23:59:16 1996
From: Paul Leach <paulle@microsoft.com>
To: "'David Kennedy'" <76702.3557@compuserve.com>,
"'www-security@ns2.rutgers.edu'" <www-security@ns2.rutgers.edu>
Date: Tue, 20 Aug 1996 19:46:20 -0700
Errors-To: owner-www-security@ns2.rutgers.edu
FYI:
We released a patch for this problem on July 3, 1996.
The patch is available at
http://www.microsoft.com/infoserv/iisservpack.htm.
>----------
>From: David Kennedy[SMTP:76702.3557@compuserve.com]
>Sent: Monday, August 19, 1996 1:16 PM
>To: The recipient's address is unknown.
>Subject: Intranet branch security
>
>>> We are using MS IIS running on an NT server. <<
>
>For intrAnet purposes, you may consider the risk acceptable:
>
>http://www.iss.net/vd/vuln/nt/ntiis.html
>
>Know the risks.
>
>Protect what you connect;
> Look both ways before crossing the Net
>
> Dave Kennedy, CISSP
>76702.3557@compuserve.com
> InfoSec Reconnaissance Team Chief
> National Computer Security Association
> Carlisle, PA
>
>