SiteServer 3.0 AdSamples installation could expose SQL server login information |
---|
Risk Level: | ![]() |
Check or Attack Name: SiteServerCSC |
---|---|---|
Platforms: | Microsoft SiteServer | |
Description: | Microsoft SiteServer 3.0 ships with an optional AdSamples directory that demonstrates the use of the Ad Server component of Site Server. If this directory is left open, it could be possible for remote attackers to retrieve a "SITE.CSC" file, which may contain database DSN's, logins, and passwords. |
|
Remedy: | Remove the AdSamples directory from all production web servers. |
|
References: | BUGTRAQ Mailing List, [ALERT] Site Server 3.0 May Expose SQL IDs and PSWs, http://www.netspace.org/cgi-bin/wa?A2=ind9905B&L=bugtraq&P=R1947 NT Security News, AdSamples Reveal ID and PSW, http://www.ntsecurity.net/scripts/loader.asp?iD=/security/siteserver-2.htm |
![]() Know Your Risks |