Customer Hosting Reviews
Search Hosts:
#  A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

Submit Review - Submit Host - Contact
Linux Hosting Reviews - Windows Hosting - Reseller Hosting - VPS Hosting - Dedicated Servers - Hosting News

Microsoft IIS Servers Hacked in Masse - 500,000 Sites


Posted on: April 28th, 2008 Respond | Trackback

Hundreds of thousands of Web sites - including several at the United Nations and in the U.K. government — have been hacked recently and seeded with code that tries to exploit security flaws in Microsoft Windows to install malicious software on visitors’ machines.

The attackers appear to be breaking into the sites with the help of a security vulnerability in Microsoft’s Internet Information Services (IIS) Web servers. In an alert issued last week, Microsoft said it was investigating reports of an unpatched flaw in IIS servers, but at the time it noted that it wasn’t aware of anyone trying to exploit that particular weakness.

On Thursday, Spanish anti-virus vendor Panda Security said that it had alerted Microsoft that a flaw IIS was the cause of all the break-ins. When I asked Microsoft whether they’d heard from Panda or if the hundreds of thousands of sites were hacked from a patched or unpatched flaw in IIS, a spokesman for the company didn’t offer much more information.

According to Finnish anti-virus maker F-Secure, the number of hacked Web pages serving up malicious software from this attack may be closer to half a million.

“The attacks are facilitated by SQL injection exploits and are not issues related to IIS 6.0, ASP, ASP.Net, or Microsoft SQL technologies,” said Bill Sisk, a communications manager at Microsoft, in a blog post. “SQL injection attacks enable malicious users to execute commands in an application’s database.”

Sisk said that to defend against SQL injection attacks, developers should follow secure coding practices.

SQL injection attacks involve insufficiently filtered code submitted to SQL databases through user input mechanisms.

On Friday, U.S. CERT issued a warning about SQL injection attacks that have compromised a large number of legitimate Web sites. Affected Web sites contain injected JavaScript that attempts to exploit several known vulnerabilities. U.S. CERT recommends disabling JavaScript and ActiveX.

Like this post? Please share: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • Reddit
  • del.icio.us
  • Netscape
  • Technorati
  • Furl
  • Slashdot
  • DZone
  • Blue Dot
  • Bumpzee
  • Gwar
  • Linkter
  • Ma.gnolia
  • MyShare
  • NewsVine
  • RawSugar
  • Simpy
  • Smarking
  • Spurl
  • YahooMyWeb
  • Netvouz

Leave a Reply

News Categories

Adult Hosting
Blog Hosting
Budget Hosting
Business Hosting
Coupon Hosting
cPanel Hosting
Dedicated Servers
Ecommerce Hosting
Linux Hosting
Reseller Hosting
VPS Hosting
Windows Hosting
Main News Page
News Archives

May 2008
April 2008
March 2008
February 2008
January 2008
December 2007
November 2007
October 2007
September 2007
Hosting Categories

Linux Hosting
Windows Hosting
Budget Hosting
Coupon Hosting
Reseller Hosting
VPS Hosting
cPanel Hosting
Business Hosting
Adult Hosting
Blog Hosting
Ecommerce Hosting
Dedicated Servers
Hosting Research

50 Latest Web Hosting Reviews
Complete Ranking Chart
Best Customer Rated Hosts
Worst Customer Rated Hosts
Hosting Coupons
Help others make the right decision!
Submit Your Web Hosting Review
Latest News

Our 8 Month Anniversary!
May 06, 2008
Microsoft IIS Servers Hacked in Masse - 500,000 Sites
Apr 28, 2008
Resellers Panel Releases Major Upgrades
Apr 25, 2008
The Planet Launched Automated Self Restore on Dedicated Servers
Apr 24, 2008
HostMySite Launches New Site Design
Apr 21, 2008
Lunarpages Windows Dedicated Servers - Special Offer
Apr 20, 2008
GoDaddy Announces Webmasters' Day
Apr 18, 2008
Lunarpages Spring Special - Save $48 Instantly!
Apr 16, 2008
See all news. Click here!
Articles

LunarPages Discount Coupon
View older articles. Click here!
Best Web Hosts

1. HostMonster
2. HostGator
3. WebHostingBuzz
4. Lunarpages
5. Web Hosting Pad
6. VistaPages
7. EasyCGI
8. HostPapa
9. HostUpon
10. Site5
RSS Feed


Newsletter
Subscribe to our Hosting News Email Newsletter
Popular Host Guides

PHP Web Hosting
Wordpress Hosting
Cheap Discount Hosting
cPanel Reseller Hosting
Ruby on Rails Web Hosting
Fantastico Hosting
Multiple Domain Hosting
Drupal Hosting
Blog Hosting
Joomla Hosting
cPanel VPS Hosting
See All Guides. Click here.
Site Friends

Wordpress Themes
LunarPages Discount
HostICan Coupon
Compare Hosting Companies
Related Sites

LunarPages Discount
HostICan Coupon
HostICan Reviews
 
Customer Hosting Reviews © 2007-2008. All Rights Reserved.

Web Hosting Categories:
Linux Hosting - Windows Hosting - Budget Hosting - Coupon Hosting - Reseller Hosting - VPS Hosting - cPanel Hosting - Business Hosting - Adult Hosting - Blog Hosting - Ecommerce Hosting - Dedicated Servers

Important Sections of Customer Hosting Reviews:
Submit a Customer Hosting Review - Submit a Hosting Company - Hosting News Blog
Hosting Articles - Web Hosting Guides