|
|
|
|
|
|
|
Index
Server Product Information
FAQ
Adobe PDF filter
Price: free with Windows NT Plus Pack and other Windows Information
Server packages
Platform: Windows NT (Server only, not Workstation), Windows 2000
Security Patches
Summer, 2001: The CodeRed Worm can attack unpatched versions of Index Server on Windows NT and Windows 2000. Exploiting this vulnerability allows attackers to run code of their choice on machines with Index Server installed.
- Microsoft Security Bulletin MS01-033: Unchecked Buffer in Index Server ISAPI Extension Could Enable Web Server Compromise
- CodeRed Advisory Notice US Government Computer Incident Advisory Center
- McAfee CodeRed Page - this incorrectly says that the worm crashes Windows NT
Spring, 2000: Microsoft has announced a Security Vulnerability with Index Server on Windows NT 4 and Windows 2000. Essentially, any site which runs Index Server can be compromised if the server receives certain erroneous commands. We recommend that everyone who is running Index Server read the FAQ and apply the patch.
Microsoft Index Server Usenet Newsgroup