2 ms·
So the disclosure mentions that there are no mitigating factors. does this mean that certain versions of windows run Http servers by default that users can't di
by earless1 11y ago
So the disclosure mentions that there are no mitigating factors. does this mean that certain versions of windows run Http servers by default that users can't disable?
That's pretty scary
- MichaelGG 11y agoI don't know if HTTP.SYS is included in every install, but you do not need to be running MS's webserver to use it. Instead of letting apps bind to port 80/443/whatever and doing HTTP themselves, MS encourages using their special interface to make the kernel listen for you. So yes, people might be accidentally running this. Does Remote PowerShell bind to HTTP.SYS or do its own thing?
- jj10 11y agoWinRM (AKA PowerShell Remoting) uses HTTP.sys and is on by default on server SKUs.
- Jayku1 11y agoWinRM and PowerShell Remoting do not use Kernel Mode Caching, and are therefore not vulnerable.
- userbinator 11y agothis mean that certain versions of windows run Http servers by default that users can't disable Apparently yes; this is on Windows 7 and above: http://www.mikeplate.com/2011/11/06/stop-http-sys-from-listening-on-port-80-in-windows/ http://www.mikeplate.com/2011/11/06/stop-http-sys-from-liste... So those on Vista or below aren't affected unless they explicitly running IIS or something else that's using HTTP.sys; and I can confirm that nothing is listening on port 80 on my XP box (nor is HTTP.sys loaded.)
- est 11y agoIf you have Windows Media Player then you have DLNA and everything and there you have to use HTTP.sys to listen on a http port. That's called Home Sharing IIRC