Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Microsoft > Security

April 29th, 2008, 10:44 GMT · By

Microsoft Says Its Technology Is Not at Fault for Massive Web Server Attacks

SHARE:

Adjust text size:


Security
Enlarge picture
Microsoft says that its technology is in no way at fault for massive web server attacks having already affected in excess of half a million webpages. The past week, security company F-Secure revealed that over 500,000 pages had been compromised through
SQL injections. The attacks target only websites that are running on Microsoft IIS Web Server and Microsoft SQL Server. However, this does not mean that the products are enabling SQL injections. Bill Sisk, Security Response Communications Manager, Microsoft brought some clarification to the issue.

"Our investigation has shown that there are no new or unknown vulnerabilities being exploited. This wave is not a result of a vulnerability in Internet Information Services or Microsoft SQL Server," Sisk revealed. The Redmond company emphasized that a privilege escalation vulnerability impacting Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008 is in no way related to the wave of SQL injections.

F-Secure confirmed that despite the fact that websites with IIS Web Server and SQL Server as their infrastructure are being hit, the "attack doesn't use vulnerabilities in any of those two applications. What makes this attack possible is poorly written ASP and ASPX (.net) code." Compromised websites will serve malicious code packages. F-Secure explained that the attacks are based exclusively on the incapacity of sites with database back-ends to properly sanitize content being uploaded, and not the result of a security flaw in IIS 6.0, ASP, ASP.Net or Microsoft SQL.

"The attacks are facilitated by SQL injection exploits and are not issues related to IIS 6.0, ASP, ASP.Net or Microsoft SQL technologies. SQL injection attacks enable malicious users to execute commands in an application's database. To protect against SQL injection attacks the developer of the Web site or application must use industry best practices," Sisk added.

TELL US WHAT YOU THINK:

1,642 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Cybercrime at the Centerstage

The Vista SP1 vs. XP SP3 Smackdown About to Start

The Ugly Side of Vista SP1 vs. XP SP3

Introducing Code-Named Albany Beta

Microsoft Presents the Lost Comparison: Windows Vista vs. Windows XP

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM