Description: A penetration test, or ethical hacking, determines how difficult it is to break into a computer network. The form of such a test varies by situation. The tests can range from a brief overview of the security of an existing infrastructure to an extensive simulated break_in, with the goal of obtaining specific information. by DaAnZeR
Description: The following X-Force Disclosure Guidelines communicate X-Force policies and procedures concerning the disclosure of vulnerability information to third-party vendors and the general public. These standards provide a careful balance between sometimes conflicting interests and are intended to be as reasonable and fair as possible to all parties involved.
Title: Microsoft IIS Unicode Exploit Explained .doc
Description: !Updated! - Microsoft Internet Information Server (ISS) versions 4.0 and 5.0 which usually runs on Windows NT4 and Windows 2k all have the Unicode extensions installed by default. Unicode allows characters that are not used in the English language to be recognized by Web Servers. The Unicode ISS Exploit allows users to run arbitrary commands on the target web servers. The Unicode extensions loaded on ISS Servers are known to be vulnerable unless they are running the current patches within the server. added by C0ldPhaTe