All the latest UK technology news, reviews and analysis

Hackers already exploiting IIS flaws

by Phil Muncaster

More from this author

05 Sep 2009

Comments: 2

  • Tweet this
Microsoft
Microsoft has yet to fix the flaws in Internet Information Services

Microsoft has revealed that hackers are already exploiting newly disclosed vulnerabilities in its Internet Information Services (IIS) web server software.

Exploit code for the first flaw was posted on Monday, allowing hackers to remotely take control of an IIS 5.0 server. New code was then posted on Thursday which takes advantage of vulnerabilities in IIS 5.0, IIS 5.1, IIS 6.0 and IIS 7.0 to allow hackers to launch denial-of-service attacks against these systems, as long as they are running the FTP Service, said Microsoft.

The company was forced to update its security advisory warning that it is now seeing "limited attacks that use this exploit code".

"Microsoft is actively monitoring this situation to keep customers informed and to provide guidance as necessary," the advisory continued.

Microsoft is due to release its September security updates on Tuesday next week, but it is widely believed that the new vulnerabilities were disclosed too recently for the Microsoft security team to deliver a working fix.

Microsoft blamed the current, albeit limited, attacks on the fact that the original vulnerabilities were published on the internet before the firm had a chance to work on a resolution.

"We continue to encourage responsible disclosure of vulnerabilities. We believe the commonly accepted practice of reporting vulnerabilities directly to a vendor serves everyone's best interests," said the firm in a blog post.

"This practice helps to ensure that customers receive comprehensive, high-quality updates for security vulnerabilities without exposure to malicious attackers while the update is being developed."

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

98%

0%

1%

0%

1%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

c# or asp.net Software Developer

Job Specification For: Software Developer...

Project Manager for UI Development

A global Investment Bank requires a Project Manager to...

Web Developer, .Net Software Developer - ASP.Net, C#, HTML, CSS

Web Developer, .Net Software Developer - ASP.Net, C...

Verint Voice Recording Support Engineer

Verint Voice Recording Support Engineer (Verint / Nice...

To send to more than one email address, simply separate each address with a comma.