News Feed
Jobs Feed
Sections




News Archive
Looking for more information on how to do PHP the right way? Check out PHP: The Right Way

Ruslan Yakushev's Blog:
ASP.NET vulnerability affecting PHP sites on IIS
September 23, 2010 @ 08:50:46

As Ruslan Yakushev points out in this new blog entry, the same security issue that's effecting ASP.NET pages running on IIS web servers can still open up PHP scripts running on the same server.

Microsoft has recently released a Security Advisory about a security vulnerability in ASP.NET. This vulnerability exists in all versions of ASP.NET. The PHP applications running on IIS are also subject to this vulnerability if ASP.NET is enabled in IIS.

The issue allows attackers to access the contents of various files on the server and could allow them to tamper with the data inside. Ruslan notes that, while Microsoft is coming up with a fix, one of the safest things you can do is either completely disable ASP.NET in the IIS server or use this workaround.

3 comments voice your opinion now!
iis vulnerability aspnet disable workaround security


blog comments powered by Disqus

Similar Posts

PHP.net: PHP 5.2.2 and PHP 4.4.7 Released

Community News: Microsoft Releases FastCGI for IIS6 as Free Download

Web & PHP Magazine: Issue #4 Published - "Safe and Secure"

PHPBuilder.com: Pro PHP Security / Preventing SQL Injection, Part 3

Symfony Blog: symfony 1.0.5 released (security fix)


Community Events











Don't see your event here?
Let us know!


symfony2 release component language opinion introduction application hhvm hack series podcast package composer framework code unittest facebook security install overview

All content copyright, 2014 PHPDeveloper.org :: info@phpdeveloper.org - Powered by the Solar PHP Framework