Security 10756 Published by

Thanks to Clutch for this one:



IISAnswers Bulletin: NT4 Sites with Redirects can crash from Code Red

It has been confirmed that despite being patched, some NT4 servers are subject to crashing when processing URLS from Code Red and its variants. This occurs on patched NT4 servers that use redirection. W2K is not affected. Those of you using redirection enabled in the IIS Snap-in should take immediate action to ensure you are not vulnerable to this problem.

This is not a problem if you use scripting to redirect your site or pages.

Microsoft evidently knows about this but has not commented on it publicly.

Below is the posting including a response from a Microsoft IIS support team member about the problem.

http://archives.neohapsis.com/archives/incidents/2001-08/0218.html