MS15-034 | Vulnerability in HTTP.sys Could Allow Remote Code Execution (3042553)
Cantor, Scott
cantor.2 at osu.edu
Thu Apr 16 14:14:56 EDT 2015
On 4/16/15, 1:53 PM, "Phil Lello" <phil at dunlop-lello.uk> wrote:
>
>Very good point. I guess it's just on my mind as I'm putting together a proposal to patch the code behind a Shib IdP RemoteUser check to chain on to an ADFS IdP rather than throwing up a form that does an LDAP-bind against AD (all part of the joy of using Office365 for email, needing a WS-Trust based IdP for things like Lync, and various internal web apps that authenticate directly against the system RemoteUser chains too).
So I guess that whole move by MS to browser login for all the apps isn't moving along very quickly then...?
-- Scott
More information about the users
mailing list