Go Back   Wireless and Wifi Forums > News > Newsgroups > comp.security.misc
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 05-02-2008, 01:18 AM
msdogfood@hotmail.com
Guest
 
Posts: n/a
Default Microsoft Security Response Center Email corespondents Fun with betatesting or NOT

http://pcneedtogo.blogspot.com/2008/...ng-or-not.html

Microsoft Security Response Center

Email corespondents


Hello
> The following is a security recommendation for the following address and domain:
> healthvault.com
> If you run an analysis using web-based networking tools such as Netcraft, healthvault.com discloses the version of web-server software is assigned to that address and the load balancer as the OS in a lot of cases. Since this service is going to be hosting private health information, it should disclose as few configuration specs as possible. The best case scenario is that it would show up as "unknown". For the record, if you ask why I am emailing you about a minor configuration issue, having such information could be used as reconnaissance for possible deeper penetration in the future. If you require more information, please let me know.
> Thanks
> msdogfood@hotmail.com


---------------------------------------------------------------------------------------




Just a quick introduction, I'm the MSRC case manager who will be
looking after this investigation moving forward.
> First of all thanks for reporting this to Microsoft responsibly we appreciate your effort in doing so.
> Right at the moment the product team is investigating your report and I hope to have some feedback fairly soon.
> In the meanwhile if you have any questions or more information please don't hesitate to contact me by replying to this email.
> I look forward to working with you on this investigation.
>
>
> Kind Regards,



----------------------------------------------------------------------------




My info & my problem.


This information was given out by the web server.



This is the output forum netcraft
http://toolbar.netcraft.com/site_rep...ealthvault.com


Hosting History
Netblock Owner IP address OS Web Server Last changed
Microsoft Corp One Microsoft Way Redmond WA US 98052 <http://
toolbar.netcraft.com/netblock?q=MICROSOFT-1BLK,
65.52.0.0,65.55.255.255> 65.55.193.143 F5 Big-IP Microsoft-IIS/6.0 4-
Oct-2007



Microsoft Security Response Center - emails me back
with this...


After further investigation, the information that we received from
HTTP response does not contain any unnecessary disclosure of
information. Some information is okay and expected to be disclosed as
while it may give a specific version information and potentially
assist in reconnaissance. Version and application information are okay
for the webserver or any other webfacing system. We would be more
concerned if information was being disclosed contained database server
information or any personally identifiable information such as
passwords, etc.

Therefore this is not a security vulnerability and we are going to
close this case. In the future, if you find any specific health
information or disclosure of SQL tables, etc. please let us know.

Thanks again for your report and please let me know if you have any
further question or concern.
------
My last email to Microsoft Security Response Center
Hi

Thank you for the email back
Thank you as well for looking into this.

I will say however that is it better if web server OS Version
information is not disclosed.
yes i do know that some information needs to be disclosed but Version
information that is optional

Regards,

Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
WTB: Nortel, Cisco, Juniper, Alcatel, Lucent, Foundry, Extreme, F5 Big IP, Tellabs, Microsoft, Adobe & more. We buy Telecom, Networking and Software. Look below at my current want to buys and email me with any offers that you have. PLEASE LOOK buyonet@hotmail.com alt.comp.hardware 0 08-26-2007 09:00 AM
WTB: Nortel, Cisco, Juniper, Alcatel, Lucent, Foundry, Extreme, F5 Big IP, Tellabs, Microsoft, Adobe and more.. We buy Telecom, Networking and Software. Look below at my current want to buys and email me with any offers that you have. Mike uk.telecom.mobile 0 06-06-2007 03:13 AM
Corrupt NTFS filesystem Citizen Bob alt.comp.hardware 144 11-11-2006 07:38 PM
Please help *PLEASE PUT ME ON YOUR EMAIL LIST* ray...i need to pay my bill and it works alt.comp.hardware 0 08-14-2006 05:51 PM
SSRT5954 rev.4 - HP-UX TCP/IP Remote Denial of Service (DoS) Security Alert comp.security.misc 0 07-12-2005 11:27 AM


All times are GMT. The time now is 04:17 AM.


Powered by vBulletin® Version 3.7.0
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0 RC4

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43