Microsoft IIS web server design weakness – causes resources exhaustion (20th Feb 2019)

Preface: Many companies do not plan to use the Microsoft IIS web server until MS SharePoint is born.

MS SharePoint baseline design: If you decide to use SharePoint, IIS web server will be work with you forever. Indeed that SharePoint products are popular. And such away let people forget about IIS web server weakness. Perhaps most of the design architect conduct the preventive control to avoid the risk already. They install a proxy server in front of IIS.

Doubt: If you have proxy server in front of IIS web server. Do you jeopardize by this vulnerability?
Perhaps your proxy will be reduce the risk. But for the long run. Schedule to do the patching.

Below is the official announcement by Microsoft.
ADV190005 – Guidance to adjust HTTP/2 SETTINGS frames

https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/ADV190005

5 thoughts on “Microsoft IIS web server design weakness – causes resources exhaustion (20th Feb 2019)”

  1. Its like you read my mind! You seem to know so much about this, like you wrote the book in it or something. I think that you can do with a few pics to drive the message home a little bit, but other than that, this is wonderful blog. A great read. I will definitely be back.

  2. I was curious if you ever considered changing the page layout of your website? Its very well written; I love what youve got to say. But maybe you could a little more in the way of content so people could connect with it better. Youve got an awful lot of text for only having one or 2 pictures. Maybe you could space it out better?|

  3. Awesome blog you have here but I was curious about if you knew of any community forums that cover the same topics discussed in this article? I’d really like to be a part of online community where I can get suggestions from other knowledgeable individuals that share the same interest. If you have any suggestions, please let me know. Cheers!|

  4. If you want to improve your familiarity only keep visiting this web page and be updated with the most recent information posted here.|

  5. This is very interesting, You’re a very skilled blogger. I’ve joined your feed and sit up for in the hunt for more of your fantastic post. Additionally, I have shared your web site in my social networks|

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.