YNOT
  • Industry News
    • Adult Business News
    • Adult Novelty News
    • YNOT Magazine
    • EU News
    • Opinions
    • Picture Galleries
  • PR Wire
    • Adult Company News
    • Adult Retail News
    • Adult Talent News
    • Adult Videos News
  • Industry Guides
    • Adult Affiliate Guide
    • Affiliate Marketing for Beginners
    • Top Adult Traffic Networks
    • Top Adult PR Agents
    • Funding an Adult Business
  • Business Directory
    • View Categories
    • View Listings
    • Submit Listing
  • Newsletters
  • Login with YNOT ID

Beware the ‘Semicolon Bug’ in Microsoft’s IIS

Posted On 29 Dec 2009
By : admin

YNOT – A punctuation mark could mean disaster for the thousands of web and intranet servers running Microsoft’s Internet Information Services, a researcher warned on Christmas Day.Cyber-security expert Soroush Dalili said semicolons are far from benign in their interactions with IIS. A vagary in the way all versions of the software parse the “;” character could allow hackers to bypass malware filters and upload malicious code simply by appending a file extension containing the punctuation mark.

“Impact of this vulnerability is absolutely high, as an attacker can bypass file extension protections by using a semicolon after an executable extension such as ‘.asp,’ ‘.cer,’ ‘.asa’ and so on,” Dalili wrote in a report dated Dec. 25. “Many web applications are vulnerable against file uploading attacks because of this weakness of IIS.”

Dalili laid out a potential scenario in an email to Britain’s The Register.

“Assume a website which only accepts JPG files as the users’ avatars,” he wrote. “And the users can upload their avatars on the server. Now an attacker tries to upload ‘Avatar.asp;.jpg’ on the server. Web application considers this file as a JPG file. So, this file has the permission to be uploaded on the server. But when the attacker opens the uploaded file, IIS considers this file as an ASP file and tries to execute it by ‘asp.dll.’

“[T]he attacker can upload a web-shell on the server by using this method. Most of the uploaders only control the last part of the files as their extensions, and by using this method, their protection will be bypassed.”

A Microsoft spokeswoman told The Register Microsoft is not aware of any semicolon attacks, but the company is investigating the reported vulnerability.

Dalili recommended webmasters who want to work around the bug ensure none of their upload directories bear execute permissions. In addition, “web developers should ensure their applications never accept the user’s input as a file name,” The Register’s Dan Goodin advised.

  • google-share
Previous Story

Erotica Website David-Nudes.com Says Quality Matters with New Site Design for 20

Next Story

Midnight Videos Co-Founder Sal Sodano Dies

Leave a Reply Cancel reply

You must be logged in to post a comment.

Sponsor

YNOT Shoot Me

YNOTShootMe.com has exclusive pics from adult industry business events. Check it out!

YNOT Directory

  • imaXcash — Dating Affiliate Network
    Dating Affiliate Programs
  • I’m Live
    Live Cam Affiliate Programs
  • CCBill
    Third Party Billing (IPSPs)
  • Premiere Listing

    The European Summit

    More Details

RECENT

POPULAR

COMMENTS

This Adult Star Just Gave 'No Pants November' a Wild Western Twist

Posted On 02 Nov 2025

How This Creator Built an 'Empire of Control' That Caught LoyalFans' Attention

Posted On 02 Nov 2025

Adult Film Studios Sue Meta Over Alleged AI Training Copyright Infringement

Posted On 02 Nov 2025

Vanessa, Meet Vivid

Posted On 29 Sep 2014
Laila Mickelwaite and Exodus Cry

Laila Mickelwaite, Exodus Cry and their Crusade Against Porn

Posted On 03 May 2021

Someone puts Gal Gadot in one of your vids? Take it down!

Posted On 13 Dec 2017

Hoping viewers can also enjoy a spooky...

Posted On 24 Oct 2023

now a days these type of games will get...

Posted On 17 Jul 2023

good move from adent. these type of...

Posted On 06 Jul 2023

Sponsor

Sitemap
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.