Customer Hosting Reviews
Search Hosts:
#  A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

Submit Web Hosting Review - Contact Customer Hosting Reviews
Linux Hosting Reviews - Windows Hosting - Reseller Hosting - VPS Hosting - Dedicated Servers - Hosting News

Microsoft IIS Servers Hacked in Masse – 500,000 Sites


Posted on: April 28th, 2008 Respond | Trackback

Hundreds of thousands of Web sites – including several at the United Nations and in the U.K. government — have been hacked recently and seeded with code that tries to exploit security flaws in Microsoft Windows to install malicious software on visitors’ machines.

The attackers appear to be breaking into the sites with the help of a security vulnerability in Microsoft’s Internet Information Services (IIS) Web servers. In an alert issued last week, Microsoft said it was investigating reports of an unpatched flaw in IIS servers, but at the time it noted that it wasn’t aware of anyone trying to exploit that particular weakness.

On Thursday, Spanish anti-virus vendor Panda Security said that it had alerted Microsoft that a flaw IIS was the cause of all the break-ins. When I asked Microsoft whether they’d heard from Panda or if the hundreds of thousands of sites were hacked from a patched or unpatched flaw in IIS, a spokesman for the company didn’t offer much more information.

According to Finnish anti-virus maker F-Secure, the number of hacked Web pages serving up malicious software from this attack may be closer to half a million.

“The attacks are facilitated by SQL injection exploits and are not issues related to IIS 6.0, ASP, ASP.Net, or Microsoft SQL technologies,” said Bill Sisk, a communications manager at Microsoft, in a blog post. “SQL injection attacks enable malicious users to execute commands in an application’s database.”

Sisk said that to defend against SQL injection attacks, developers should follow secure coding practices.

SQL injection attacks involve insufficiently filtered code submitted to SQL databases through user input mechanisms.

On Friday, U.S. CERT issued a warning about SQL injection attacks that have compromised a large number of legitimate Web sites. Affected Web sites contain injected JavaScript that attempts to exploit several known vulnerabilities. U.S. CERT recommends disabling JavaScript and ActiveX.

Web Hosting News to Share and Enjoy:
  • Print this article!
  • Digg
  • Facebook
  • del.icio.us
  • Twitter
  • Mixx
  • Google Bookmarks
  • Technorati
  • Yahoo! Bookmarks
  • Reddit
  • StumbleUpon
  • Sphinn
  • LinkedIn
  • Live

Leave a Reply

News Categories

Adult Hosting
Blog Hosting
Budget Hosting
Business Hosting
Coupon Hosting
cPanel Hosting
Dedicated Servers
Ecommerce Hosting
Linux Hosting
Reseller Hosting
VPS Hosting
Windows Hosting
Main News Page
News Archives

September 2009
August 2009
May 2008
April 2008
March 2008
February 2008
January 2008
December 2007
November 2007
October 2007
September 2007
Hosting Categories

Linux Hosting
Windows Hosting
Budget Hosting
Coupon Hosting
Reseller Hosting
VPS Hosting
cPanel Hosting
Business Hosting
Adult Hosting
Blog Hosting
Ecommerce Hosting
Dedicated Servers
Hosting Research

50 Latest Web Hosting Reviews
Complete Ranking Chart
Best Customer Rated Hosts
Worst Customer Rated Hosts
Hosting Coupons
Help others make the right decision!
Submit Your Web Hosting Review
Latest News

Bluehost Web Hosting Deals
Sep 05, 2009
HostMonster Web Hosting Coupon Discount
Sep 05, 2009
HostGator Web Hosting Coupon
Sep 05, 2009
LunarPages Latest Offers - 2009
Aug 01, 2009
Just Host Web Hosting Coupon
Aug 01, 2009
HostICan Coupon Special Offer - $3.78/Mo Hosting
Aug 01, 2009
See all news. Click here!
Articles

Professional WordPress Theme SumsyGreen
LunarPages Discount Coupon
View older articles. Click here!
Best Web Hosts

1. HostMonster
2. HostGator
3. InMotion Hosting
4. HostICan
5. BlueHost
6. Just Host
7. FastDomain
8. Lunarpages
9. Web Hosting Pad
10. EasyCGI
RSS Feed


Newsletter
Subscribe to our Hosting News Email Newsletter
Popular Host Guides

PHP Web Hosting
Wordpress Hosting
Cheap Discount Hosting
cPanel Reseller Hosting
Ruby on Rails Web Hosting
Fantastico Hosting
Multiple Domain Hosting
Drupal Hosting
Blog Hosting
Joomla Hosting
cPanel VPS Hosting
See All Guides. Click here.
Site Friends

VPS Hosting
VPS Reviews
Wordpress Themes
LunarPages Discount
HostICan Coupon
Compare Hosting Companies
Related Sites

HostICan Coupon
LunarPages Discount
HostICan Reviews
 
Customer Web Hosting Reviews © 2007-2010. All Rights Reserved.
Submit a Web Hosting Review - Contact Us

Hosting Reviews by Category:
Linux Hosting Reviews - Windows Hosting Reviews - Budget Hosting Reviews - Coupon Hosting Reviews
Reseller Hosting Reviews - VPS Hosting Reviews - cPanel Hosting Reviews - Business Hosting Reviews
Adult Hosting Reviews
- Blog Hosting Reviews - Ecommerce Hosting Reviews - Dedicated Servers Reviews

We Use and Recommend:
HostMonster Reviews - HostGator Reviews - Lunarpages Reviews - HostICan Reviews - BlueHost Reviews