* Web-based Distributed Authoring and Versioning
Everyone’s looking for an easy secure way to let users share and collaborate on corporate documents. It just makes life easier. Fortunately our Technology Update topic this week defines a methodology for doing just that; unfortunately it has been in the news lately because of a security flaw.
I am talking about Web-based Distributed Authoring and Versioning (WebDAV). Basically, WebDAV is a set of extensions to HTTP that lets users edit and manage files on remote Web servers. The protocol is designed to create interoperable, collaborative applications that can be used across a wide swath of enterprise environments.
According to this week’s Tech Update author (ldusseault@xythos.com) WebDAV can be found in Web servers such as Apache and Microsoft Internet Information Server (IIS) and now is supported by document and content management vendors as well. WebDAV functionality also is embedded in common desktop operating systems including Windows and Mac OS X, and popular applications from Adobe, Lotus, Microsoft and others.
Unfortunately last month Microsoft had to develop a patch for security breach in a Windows 2000 component called ntdll.dll that is used to handle WebDAV transactions. An attacker could use the vulnerability to cause a buffer overflow on the machine running Microsoft’s IIS to create a denial-of-service attack against such machines or execute their own malicious code in the security context of the IIS service, giving them unfettered access to the vulnerable system, Microsoft said. (See Microsoft Security bulletin MS03-007: https://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-007.asp)
For more on out Technology Update see: https://www.nwfusion.com/tech/2003/0407techupdate.html




