FYI…

- http://isc.sans.org/diary.php?storyid=944
Last Updated: 2005-12-19 20:47:01 UTC
"A Denial of Service (DoS) exploit against IIS 5.1 was brought to our attention. Source code of the exploit is being distributed from multiple sites. The claimed effect of the exploit is to stop the inetinfo.exe process. We have advised Microsoft of the situation and got a reply they are aware and are investigating. We're eager to see more details from Microsoft. The troubling part is the simplicity of the URL used in the exploit, so an understanding of what it causes on the server would be very interesting from a security perspective.
Vulnerable versions
Confirmation of the exact conditions where the exploit works will cause updates to this story. IIS 5.1 comes with Windows XP Professional, but fortunately isn't enabled by default. Even if most professionals will try to avoid using Windows XP on a server, some other software installation might have decided it was a good idea to enable it…"

- http://secunia.com/advisories/18106/
Release Date: 2005-12-19
Critical: Moderately critical
Impact: DoS
Where: From remote
Solution Status: Unpatched
…Note: IIS will automatically restart after the crash.
The vulnerability has been confirmed in IIS 5.1 on a full patched version of Microsoft Windows XP SP2.
Solution:
Filter potential malicious characters or character sequences with a HTTP proxy.
IIS 5.0 and 6.0 are reportedly -not- affected…"

:ph34r: