Yukon and HTTP.SYS revisited

Security Briefs

Syndication

Dan Sullivan pointed out sp_delete_http_namespace_reservation - this is apparently how you undo sp_reserve_http_namespace.

Dan was one of the three authors of the authoritative book on Yukon, A First Look at SQL Server 2005. You should pick it up if you're working in that space.

Thanks Dan!


Posted Jun 26 2005, 09:49 PM by keith-brown
Filed under:

Comments

mihailik wrote re: Yukon and HTTP.SYS revisited
on 06-29-2005 2:40 AM
Keith, may I ask you to tell about System.Net.HttpListener?

This new component based on HTTP.SYS, but there is no way to use it from non-admin acount. As you are Security guy, you should know how it is crazy to open inbound HTTP connection with admin privileges.

May be you can share the security scenario of this component.
Keith Brown wrote re: Yukon and HTTP.SYS revisited
on 07-01-2005 10:05 AM
As long as you reserve a set of prefixes ahead of time, you should be able to use HttpListener from a non-privileged account. I've not yet played with HttpListener myself, but if you look at Gudge's post, he shows how to use httpcfg to manage reservations.

http://pluralsight.com/blogs/keith/archive/2005/06/23/11906.aspx#FeedBack
mihailik wrote re: Yukon and HTTP.SYS revisited
on 07-01-2005 10:30 AM
Thank you very much, Keith. I'l try to realize how to use it right way.

And congratulations of became Visual Developer Security MVP! We are two from nine currently :-)
Dinis Cruz @ Owasp .Net Project wrote Http.Sys research
on 11-28-2005 3:19 AM


INF: Http.sys Registry Settings for IIS
Using Http.Sys to receive messages with WSE 2.0 , HTTP.SYS...

Add a Comment

(required)  
(optional)
(required)  
Remember Me?