TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Triggering MS14-066

13 pointsby PaulSecover 10 years ago

1 comment

ecairnsover 10 years ago
OK, so I admittedly don't have the time to fully analyze this, but it looks like the bug is in the code that processes client certificates. The default setting in IIS is to ignore client certificates so does that mean that by default you can't trigger this exploit against an out of the box IIS setup?