<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.architectingconnectedsystems.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>CJG : _vti_bin</title><link>http://blogs.architectingconnectedsystems.com/blogs/cjg/archive/tags/_5F00_vti_5F00_bin/default.aspx</link><description>Tags: _vti_bin</description><dc:language>en</dc:language><generator>CommunityServer 2.1 (Build: 60809.935)</generator><item><title>Most Commonly Missed Best Practice with Internet Sites</title><link>http://blogs.architectingconnectedsystems.com/blogs/cjg/archive/2009/02/11/Most-Commonly-Missed-Best-Practice-with-Internet-Sites.aspx</link><pubDate>Wed, 11 Feb 2009 22:22:00 GMT</pubDate><guid isPermaLink="false">4aac0a7f-2495-46e5-9eb3-fa68b32063a9:37</guid><dc:creator>cjg</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.architectingconnectedsystems.com/blogs/cjg/comments/37.aspx</comments><wfw:commentRss>http://blogs.architectingconnectedsystems.com/blogs/cjg/commentrss.aspx?PostID=37</wfw:commentRss><description>&lt;p&gt;Wanna know what it is?&amp;nbsp; It is a disaster waiting to happen!&amp;nbsp;&amp;nbsp; &lt;br /&gt;&lt;/p&gt;&lt;p&gt;Some day an IIS 6.0 vulnerability will come out that allows you to get administrator access to the _vti_bin directory of your SharePoint site.&amp;nbsp; You will then be able to execute a call to the Lists web service and delete the &amp;quot;Pages&amp;quot; document library! &amp;nbsp;&lt;/p&gt;&lt;p&gt;To prove it, do a search on Pages/default.aspx in google.&amp;nbsp; You will get a listing on all the sites on the internet that are running sharepoint as their internet site.&amp;nbsp; Check their _vti_bin directory access by appending /_vti_bin/lists.asmx&lt;/p&gt;&lt;p&gt;&amp;nbsp;If you get the web service page for the list service, that company has setup there site WRONG!&lt;/p&gt;&lt;p&gt;The correct way of doing things is to create an extended web application that HAS the _vti_bin and the original with the _vti_bin DELETED!&amp;nbsp; The original is the internet accessable one and the extended one is accessible only by internal staff (so you can use SharePoint Designer and such).&lt;/p&gt;&lt;p&gt;Anyone feel like writing a vulnerability and the code to delete all the pages&amp;nbsp; document libraries on the internet to prove my point???&amp;nbsp; Couldn&amp;#39;t be too hard :)&lt;/p&gt;&lt;p&gt;CJG &lt;br /&gt;&lt;/p&gt;&lt;img src="http://blogs.architectingconnectedsystems.com/aggbug.aspx?PostID=37" width="1" height="1"&gt;</description><category domain="http://blogs.architectingconnectedsystems.com/blogs/cjg/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.architectingconnectedsystems.com/blogs/cjg/archive/tags/_5F00_vti_5F00_bin/default.aspx">_vti_bin</category></item></channel></rss>