Latest Comments
"Excellent info. If you use Gumtree Australia you will see many obvious scam posts in all ..."
by Marian Imrie | Dec 5, 2008 4:45 PM
 
"Very nice and useful information. UT4B4. Tape4backup.com"
by Lto-4 Tape | Dec 4, 2008 9:23 PM
 
"Interesting that you do not bother to list the one AV that has consistently passed the VB100. ..."
by Ben | Dec 4, 2008 6:00 PM
 
"I like this"
by nanwin | Dec 3, 2008 3:05 PM
 
"Concerned man's comments seem to intimate that if I'm using agents all will be well but the ..."
by Werner K | Nov 26, 2008 8:36 PM
Web

Microsoft denies mass web-attack result of vulnerabilities

  • Email a Friend
  • Print Page
Microsoft denies mass web-attack result of vulnerabilities
By Negar Salek
Apr 28, 2008 3:24 PM
Tags: "microsoft" | "sql | injections" | "website | security" | "internet | security"
Panda Security told SC US last week that hackers are injecting SQL code in web pages by taking advantage of a vulnerability in Microsoft's Internet Information Services (IIS) web server as part of the mass attack.

In response, Bill Sisk wrote in Microsoft's Security Response Center blog on Friday that the attacks are not a result of a vulnerability in Internet Information Services or Microsoft SQL Server.

“There are no new or unknown vulnerabilities being exploited. The attacks are facilitated by SQL injection exploits and are not issues related to IIS 6.0, ASP, ASP.Net or Microsoft SQL technologies.”

Furthermore, Microsoft have determined that these attacks are in no way related to Microsoft Security Advisory 951306.

Agreeing, Patrik Runald, security response manager at F-Secure said in his security blog the attacks exist by poorly written ASP and ASPX (.net) code. However, he admitted the vendor had only detected websites using Microsoft IIS web server and Microsoft SQL Server being hit.

Well over 500,000 websites were affected by the attack, warned F-Secure. While Runald said it’s crucial to verify what information gets stored in databases and back ends.

“Especially if you allow users to upload content themselves, which happens all the time in discussion forums, blogs, feedback forms, unless that data is sanitised before it gets saved you can't control what the website will show to the users,” he said.

“This is what SQL injection is all about, exploiting weaknesses in these controls. In this case the injection code starts off like this (note, this is not the complete code).”

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
Vulnerabilities & Exploits Whitepapers