April 26, 2008
10:33 pm

There have been conflicting public reports describing a recent rash of web server attacks. I want to bring some clarification about the reports and point you to the IIS blog for additional information.

To begin with, our investigation has shown that there are no new or unknown vulnerabilities being exploited. This wave is not a result of a vulnerability in Internet Information Services or Microsoft SQL Server. We have also determined that these attacks are in no way related to Microsoft Security Advisory (951306).

The attacks are facilitated by SQL injection exploits and are not issues related to IIS 6.0, ASP, ASP.Net or Microsoft SQL technologies. SQL injection attacks enable malicious users to execute commands in an application's database.  To protect against SQL injection attacks the developer of the Web site or application must use industry best practices outlined here.  Our counterparts over on the IIS blog have written a post with a wealth of information for web developers and IT Professionals can take to minimize their exposure to these types of attacks by minimizing the attack surface area in their code and server configurations.

More infoIIS.net

Source:→ Microsoft

Microsoft, IIS, SQL Server, Security, Web Server, Intrusion, Hacking, SQL Injection, Exploit, Security, Security Advisory

Loading

Contextual Related Posts:

2 Responses | RSS comments on this post | Leave a comment»

  1. 1
    DG says#2 | April 28th, 2008 at 8:18 pm

    Thanks Nico, for the information/link.

  2. 2
    Nico says#1 | April 28th, 2008 at 7:05 pm

    We have a great video tutorial on proofing against SQL injection attacks on the Hello Secure World website, too, but your outlined best practices are right on target. I hope more IT professionals keep that URL handy if they don't already.
    **************
    Nico del Castillo
    Microsoft Security Outreach Team
    http://www.microsoft.com/hellosecureworld/level7

No Pingback yet

PingBack URI

Leave a Response

Comment Preview
« Origami Experience 2.0Live Mesh invite for free! »
Feed Icon

Subscribe via RSS or email: