All the latest UK technology news, reviews and analysis

Concern grows over 'secret' hacking tool

by James Middleton

25 Jun 2001

Be the first to comment

  • Tweet this

Security professionals are concerned that a program used by hackers to exploit a flaw in Microsoft IIS webserver has not been made public. They fear that the hackers are keeping the tool secret in a bid to launch further damaging IIS attacks.

The latest in a long line of vulnerabilities in IIS was discovered last week, when it was revealed that a remote buffer overflow in all versions of IIS Internet Services API could be exploited to give an attacker complete control of a system.

But the security community is worried that hackers may be hanging on to the tool used for exploiting this hole, rather than releasing it for analysis so that a patch can be developed.

Typically, when a hole is discovered, a tool capable of exploiting the glitch appears within 48 hours, encouraging administrators to patch their systems quickly.

But so far, no such tool has appeared to push administrators into gear, although rumour has it that hackers are in possession of such a program, potentially leaving the six million users of IIS at risk.

Security firm @stake warned that administrators are less likely to react to an advisory if there is no exploit tool available.

Hackers thrive on a lack of awareness in security and, by keeping the exploit tool underground, network administrators could be lulled into a false sense of security.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

C++ GUI Developer - Financial Services - London

C++ GUI Developer - Financial Services - London Tech...

Java Web Developer, Greenfield Trading Application

This is an opportunity for a bright and talented Java...

C# Application Developer

C# Application Developer Location : Nottingham...

Senior HTML Developer

Experienced Web Developer Wanted for Financial Sector...

To send to more than one email address, simply separate each address with a comma.