Groups | Blog | Home
all groups > iis security > june 2007 >

iis security : how to update IIS SP


chiragbudhbhatti NO[at]SPAM gmail.com
6/18/2007 5:22:14 AM
Hi All,

Please let me know how to update IIS Service pack, I have update
windows 2003 SP 2 but still I'm getting error as below:

Synopsis : The remote web server is running Microsoft IIS.
Description : The Patch level
(Service Pack) of the remote IIS server appears to be lower than the
current IIS service pack
level. As each service pack typically contains many security patches,
the server may be at risk.
Note that this test makes assumptions of the remote patch level based
on static return values
(Content-Length) within a IIS Server's 404 error message. As such, the
test can not be totally
reliable and should be manually confirmed. Note also that, to
determine IIS6 patch levels, a
simple test is done based on strict RFC 2616 compliance. It appears as
if IIS6-SP1 will accept
CR as an end-of-line marker instead of both CR and LF. Solution:
Ensure that the server is
running the latest stable Service Pack. Risk Factor: None Plugin
output : The remote IIS
server *seems* to be Microsoft IIS 6.0 - SP1

Thanks in Advance
Bernard Cheah [MVP]
6/19/2007 12:00:00 AM
There's no specific IIS service pack. SP only applies to OS.
what scanner you using? what's the mitigation action beside asking to you
apply the lastest so called IIS SP ?


--
Regards,
Bernard Cheah
http://www.iis.net/
http://www.iis-resources.com/
http://msmvps.com/blogs/bernard/


[quoted text, click to view]

sjohnson NO[at]SPAM creditorsinterchange.com
7/30/2007 5:51:40 AM
On Jun 19, 12:48 am, "Bernard Cheah [MVP]"
[quoted text, click to view]

We are using Nessus and I installed SP2 for 2003 this past weekend.
Still get the same as the OP
AddThis Social Bookmark Button