Re: ISA Cross Scripting Vulnerability KB article

  • From: "John G. Lyon" <jlyon@xxxxxxxxxxxxx>
  • To: "[ISAserver.org Discussion List]" <isalist@xxxxxxxxxxxxx>
  • Date: Thu, 17 Jul 2003 12:26:27 -0400

Roger I installed it on a remote machine while VPN'd into it. The only service 
it stopped started was Webproxy. It didn't warn ahead of time, your right. Just 
warned as it was doing so in a pop up

        -----Original Message----- 
        From: Rogers, Brian [mailto:RogersB@xxxxxxxxxxxxxx] 
        Sent: Thu 7/17/2003 11:45 AM 
        To: [ISAserver.org Discussion List] 
        Cc: 
        Subject: [isalist] Re: ISA Cross Scripting Vulnerability KB article
        
        
        http://www.ISAserver.org
        
        
        

        Tell whoever made the EXE to include information that it will restart 
the services without warning immediately after accepting the EULA next time :)

        -----Original Message----- 
        From: Jim Harrison [mailto:jim@xxxxxxxxxxxx] 
        Sent: Thursday, July 17, 2003 11:14 AM 
        To: [ISAserver.org Discussion List] 
        Subject: [isalist] Re: ISA Cross Scripting Vulnerability KB article 

        http://www.ISAserver.org 


        Thanks, Tom; I'll see to it that your praise is felt by the right 
folks! 

         Jim Harrison 
         MCP(NT4, W2K), A+, Network+, PCG 
         http://www.microsoft.com/isaserver 
         http://isaserver.org/Jim_Harrison 
         http://isatools.org 

         Read the help, books and articles! 
        ----- Original Message ----- 
        From: "Thomas W Shinder" <tshinder@xxxxxxxxxxxxxxxxxx> 
        To: "[ISAserver.org Discussion List]" <isalist@xxxxxxxxxxxxx> 
        Sent: Thursday, July 17, 2003 07:29 
        Subject: [isalist] ISA Cross Scripting Vulnerability KB article 


        http://www.ISAserver.org 


        Hey! 

        This Security Alert: 

        
http://www.microsoft.com/technet/treeview/?url=/technet/security/bulleti 
        n/MS03-028.asp 

        Has to be one of the best written sec alerts on the site. Not only does 
        it give the details of the problem, it goes through the issue of what 
        XSS is, how it works, and how it relates to this alert. 

        The typical sec alert essentially says "someone found this thing is 
        broken, here is some obfuscatory reasons why its broken, and if you 
        don't understand, too bad and oh, we're not going to give any 
examples". 

        My hat's off to the author of MS03-028! 

        Thanks! 
        Tom 
        Thomas W Shinder 
        www.isaserver.org/shinder <http://www.isaserver.org/shinder> 
        ISA Server and Beyond: http://tinyurl.com/1jq1 
        Configuring ISA Server: http://tinyurl.com/1llp 
        <http://tinyurl.com/1llp> 





        ------------------------------------------------------ 
        List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist 
        ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp 
        ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ 
        ------------------------------------------------------ 
        Other Internet Software Marketing Sites: 
        Leading Network Software Directory: http://www.serverfiles.com 
        No.1 Exchange Server Resource Site: http://www.msexchange.org 
        Windows Security Resource Site: http://www.windowsecurity.com/ 
        Network Security Library: http://www.secinf.net/ 
        Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com 
        ------------------------------------------------------ 
        You are currently subscribed to this ISAserver.org Discussion List as: 
        jim@xxxxxxxxxxxx 
        To unsubscribe send a blank email to 
leave-isalist-1464356Y@xxxxxxxxxxxxx 


        ------------------------------------------------------ 
        List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist 
        ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp 
        ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ 
        ------------------------------------------------------ 
        Other Internet Software Marketing Sites: 
        Leading Network Software Directory: http://www.serverfiles.com 
        No.1 Exchange Server Resource Site: http://www.msexchange.org 
        Windows Security Resource Site: http://www.windowsecurity.com/ 
        Network Security Library: http://www.secinf.net/ 
        Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com 
        ------------------------------------------------------ 
        You are currently subscribed to this ISAserver.org Discussion List as: 
rogersb@xxxxxxxxxxxxxx 
        To unsubscribe send a blank email to 
leave-isalist-1464356Y@xxxxxxxxxxxxx 

        ------------------------------------------------------
        List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist
        ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp
        ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ
        ------------------------------------------------------
        Other Internet Software Marketing Sites:
        Leading Network Software Directory: http://www.serverfiles.com
        No.1 Exchange Server Resource Site: http://www.msexchange.org
        Windows Security Resource Site: http://www.windowsecurity.com/
        Network Security Library: http://www.secinf.net/
        Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com
        ------------------------------------------------------
        You are currently subscribed to this ISAserver.org Discussion List as: 
jlyon@xxxxxxxxxxxxx
        To unsubscribe send a blank email to 
leave-isalist-1464356Y@xxxxxxxxxxxxx 

Other related posts: