I have been working with Rain Forest Puppy researching this....
It looks like you will only be affected if you are running an MDAC older
than 2.0. The Jet Database Engine 3.51 is the engine that had the
exploitable vulnerability. Jet Database Engine 4.0 corrects this. RFP
should be releasing an update to Bugtraq in the next day or so.
I have written a test exploit .asp script that will test to see if you are
vulnerable. You can e-mail me directly for a copy of the test script.
Scott R. Chrestman
Vice President
Netropolis Communications Corp.
E-Mail: [EMAIL PROTECTED]
http://www.netropolis.net
�
> -----Original Message-----
> From: [EMAIL PROTECTED]
> [mailto:[EMAIL PROTECTED]]On Behalf Of James
> Strompolis
> Sent: Thursday, May 27, 1999 10:59 AM
> To: Undisclosed-Recipient:@elmls02.ce.mediaone.net;
> Subject: [IMail Forum] ODBC security flaw with NT IIS
>
>
> To all you folks using an external database and web interface to
> ODBC, take
> a look at this:
>
http://www.geek-girl.com/bugtraq/1999_2/0544.html
James Strompolis
Aleph Consultants, Inc.
[EMAIL PROTECTED], http://www.ribs.com