VPS Hosting Reviews
Search VPS Hosts:
#  A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

VPS Hosting Reviews - cPanel VPS - Plesk Linux VPS - Plesk Windows VPS - DirectAdmin VPS - Hybrid VPS - News

Microsoft IIS Servers Hacked in Masse - 500,000 Sites


Posted on: April 28th, 2008 Respond | Trackback

Hundreds of thousands of Web sites - including several at the United Nations and in the U.K. government — have been hacked recently and seeded with code that tries to exploit security flaws in Microsoft Windows to install malicious software on visitors’ machines.

The attackers appear to be breaking into the sites with the help of a security vulnerability in Microsoft’s Internet Information Services (IIS) Web servers. In an alert issued last week, Microsoft said it was investigating reports of an unpatched flaw in IIS servers, but at the time it noted that it wasn’t aware of anyone trying to exploit that particular weakness.

On Thursday, Spanish anti-virus vendor Panda Security said that it had alerted Microsoft that a flaw IIS was the cause of all the break-ins. When I asked Microsoft whether they’d heard from Panda or if the hundreds of thousands of sites were hacked from a patched or unpatched flaw in IIS, a spokesman for the company didn’t offer much more information.

According to Finnish anti-virus maker F-Secure, the number of hacked Web pages serving up malicious software from this attack may be closer to half a million.

“The attacks are facilitated by SQL injection exploits and are not issues related to IIS 6.0, ASP, ASP.Net, or Microsoft SQL technologies,” said Bill Sisk, a communications manager at Microsoft, in a blog post. “SQL injection attacks enable malicious users to execute commands in an application’s database.”

Sisk said that to defend against SQL injection attacks, developers should follow secure coding practices.

SQL injection attacks involve insufficiently filtered code submitted to SQL databases through user input mechanisms.

On Friday, U.S. CERT issued a warning about SQL injection attacks that have compromised a large number of legitimate Web sites. Affected Web sites contain injected JavaScript that attempts to exploit several known vulnerabilities. U.S. CERT recommends disabling JavaScript and ActiveX.

Like this post? Please share: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • bodytext
  • Reddit
  • del.icio.us
  • Netscape
  • Technorati
  • Furl
  • Slashdot
  • description
  • Blue Dot
  • Bumpzee
  • Gwar
  • Linkter
  • Ma.gnolia
  • MyShare
  • NewsVine
  • RawSugar
  • Simpy
  • Smarking
  • Spurl
  • YahooMyWeb
  • Netvouz

Leave a Reply

News Categories

cPanel Linux VPS
cPanel Windows VPS
DirectAdmin VPS
Hybrid VPS
Other VPS
Plesk Linux VPS
Plesk Windows VPS
Webmin VPS
Main News Page
News Archives

April 2008
March 2008
February 2008
January 2008
VPS Categories

cPanel Linux VPS
cPanel Windows VPS
Plesk Linux VPS
Plesk Windows VPS
DirectAdmin VPS
Webmin VPS
Hybrid VPS
Other VPS
Top VPS Guides

Linux VPS Hosting
What is a VPS
SSH Root Access
Windows VPS Hosting
Is a VPS Right For Me
VPS Advantages
VPS Disadvantages
cPanel VPS Hosting
Plesk VPS Hosting
VPS Control Panel Options
See All Guides. Click here.
VPS Research

50 Latest VPS Reviews
Full VPS Ranking
Top Rated VPS Hosts
Worst VPS Hosts
VPS Coupons
Latest VPS News

Microsoft IIS Servers Hacked in Masse - 500,000 Sites
Apr 28, 2008
HostV VPS Discount Coupon - 50% Off
Apr 27, 2008
70 New VPS Hosts Added
Apr 26, 2008
GoDaddy Announces Webmasters' Day
Apr 17, 2008
LunarPages VPS Virtual Private Server March News
Mar 26, 2008
HostICan Upgrades VPS RAM by 50%!
Mar 25, 2008
ServINT Enhancements Announced
Mar 12, 2008
Blogging on VPS Host Reviews
Feb 18, 2008
See all news. Click here!
VPS Articles

LunarPages VPS Discount Coupon
View older articles. Click here!
Top 10 VPS Hosts

1. VPSNext
2. LiquidWeb
3. HostICan
4. Lunarpages
5. EasyCGI
6. TigerServers
7. RapidVPS
8. InMotion Hosting
9. StartLogic
10. ModVPS

Our lab results.
RSS Feed


Newsletter
Subscribe to our VPS News Email Newsletter
Site Friends

Shared Hosting Reviews
Related Sites

LunarPages Discount
HostICan Reviews
HostICan Coupon
 
VPS Hosting Reviews © 2008. All Rights Reserved.

Web Hosting Categories:
cPanel Linux VPS - cPanel Windows VPS - Plesk Linux VPS - Plesk Windows VPS
DirectAdmin VPS - Webmin VPS - Hybrid VPS - Generic VPS
Need Shared? Simple Web Hosting

Important Sections of VPS Hosting Reviews:
Submit a VPS Host Review - Submit a VPS Host - VPS News Blog
VPS Articles - VPS Hosting Guides