in

User Forum

Sharing ideas, experience and creative content.

Content Server Vulnerability

Last post 05-28-2009 3:18 PM by JeffHall. 3 replies.
Page 1 of 1 (4 items)
Sort Posts: Previous Next
  • 05-26-2009 1:39 PM

    Content Server Vulnerability

    I work at a large university and our Axis content server was recently quarantined by our IT department because "The Information Security Office has found the following system has one or more outstanding high-risk Microsoft vulnerabilities which requires your immediate attention. ... In this case, an attacker could send a specially constructed request which crashes the server, executes arbitrary code with the privileges of the web server, bypasses access restrictions on WebDAV server, or reveals the source code of ASP pages. More information about the specific vulnerabilities that were assessed can be found at: http://www.microsoft.com/technet/security/advisory/971492.mspx "

    Our server has the default settings from Visix and we've updated Windows XP reguarly with critical updates, including Service Pack 3. Is Visix aware of this potential vulnerabilty and do they have a recommended fix?   We suspect some settings relating to WebDAV or annonymous user access need to be modified, but don't want to make any big changes without knowing for sure.

  • 05-28-2009 2:59 PM In reply to

    Re: Content Server Vulnerability

    After reviewing the Microsoft Security Advisory concerning the recently exposed Vulnerability in Internet Information Services, Visix suggest using one of the Microsoft listed workarounds: ·         Disable WebDAV - Microsoft Knowledge Base Article 241520.By disabling off WebDav, the end user will disable the mechanism the hacker can use to exploit the found vulnerability. The issue being reported also needs to be thought of from an infrastructure standpoint. If you are running the AxisTV program on an externally facing webserver the end user will be at a higher risk. The majority of the AxisTV users are using a local intranet which is not exposed to the external internet. This reduces the risk of an anonymous hacker exploiting the vulnerability in IIS.

     

  • 05-28-2009 3:08 PM In reply to

    Re: Content Server Vulnerability

    Thanks, Jeff. Our server is accessed from channel players in other cities, so we are more open to the world. So in the end, we decided to put up firewalls to only allow access with our channel players and individuals who need to update content. So we're back up and running and more secure than ever.

    Marc

  • 05-28-2009 3:18 PM In reply to

    Re: Content Server Vulnerability

    Thanks for the update and that is very good news. Please let us know if we can be of assitance.

Page 1 of 1 (4 items)
© Copyright 2009-2012 Visix, Inc. All rights reserved.
Powered by Community Server (Commercial Edition), by Telligent Systems