Forum     

Go Back   Digit Technology Discussion Forum > News > Technology News
Register FAQ Calendar Mark Forums Read

Technology News News from the world of technology that our members stumble across. NOTE: Sources to be mentioned at the beginning of each post.


Closed Thread
 
LinkBack Thread Tools Display Modes
Old 29-04-2008, 07:46 PM   #1 (permalink)
Unmountable Boot Volume
 
Cyrus_the_virus's Avatar
 
Join Date: Sep 2007
Location: Kerala
Posts: 907
Exclamation Hundreds of Thousands of Microsoft Web Servers Hacked


Hundreds of thousands of Web sites - including several at the United Nations and in the U.K. government -- have been hacked recently and seeded with code that tries to exploit security flaws in Microsoft Windows to install malicious software on visitors' machines.
The attackers appear to be breaking into the sites with the help of a security vulnerability in Microsoft's Internet Information Services (IIS) Web servers. In an alert issued last week, Microsoft said it was investigating reports of an unpatched flaw in IIS servers, but at the time it noted that it wasn't aware of anyone trying to exploit that particular weakness.

On Thursday, Spanish anti-virus vendor Panda Security said that it had alerted Microsoft that a flaw IIS was the cause of all the break-ins. When I asked Microsoft whether they'd heard from Panda or if the hundreds of thousands of sites were hacked from a patched or unpatched flaw in IIS, a spokesman for the company didn't offer much more information.

"Microsoft is currently aware of and is receiving reports regarding public claims of attacks on IIS Web servers," said Bill Sisk, a security response manager at Microsoft, in a statement e-mailed to Security Fix. "While we have not be [sic] contacted directly regarding these reports, we will continue to monitor all reports either publically [sic] shared or responsibly disclosed and investigate once sufficient details are provided. We have not yet determined whether or not these reports are related to Microsoft Security Advisory (951306) released last week."

According to Finnish anti-virus maker F-Secure, the number of hacked Web pages serving up malicious software from this attack may be closer to half a million.

Dancho Danchev, an independent security analyst, has a decent write-up on signs that Web site owners can look for to tell whether their site has been hit by this attack. Danchev said all of the hacked sites appear to have Javascript coding adding to their page source that silently pulls down malware from a few domains in China, namely nihaorr1.com, and haoliuliang.net.

Needless to say, if you run a Google search for these sites you will find tens of thousands that contain the script that redirects any visitors to these malicious sites. I would strongly urge people to steer clear of those sites: I mention them here so that Web site owners can more easily search the HTML code in their pages for these domains.

There are indications that this attack is coming in waves, with the bad guys swapping in new malicious downloader sites every few days. According to posts on an IIS user forum, Web site administrators first saw signs of this attack on April 17, the day before Microsoft issued its initial advisory on the IIS vulnerability.

If you run your site with IIS, please take a moment to consider applying the workarounds in the Microsoft advisory for your version of IIS. Also, that IIS.net post I mentioned earlier has some great tips to help administrators lock down their systems.

These types of attacks that infiltrate legitimate, trusted Web sites are precisely the reason I so often recommend Firefox over Internet Explorer. There is a great add-on for Firefox called "noscript," which blocks these kinds of Javascript exploits from running automatically if a user happens to visit a hacked site. Currently, there is no such protection for IE users, and disallowing Javascript entirely isn't really an option on today's World Wide Web. True, you can fiddle with multiple settings in IE to add certain sites to your "Trusted Zone," but that option has never struck me as very practical or scalable.

Source: Washington post


Quote:
Security expert: Don't blame Microsoft for mass site defacements

Progress was made Monday in mitigating thousands of SQL-based Web sites injected with malicious Javascript code. However, one security expert says we can expect more such attacks in the near future.

A traditional SQL injection attack allows malicious attackers to execute commands on an application's database by injecting executable code. "What's different about this latest attack is the size and the level of sophistication," said Jeremiah Grossman, CTO of White Hat Security.


On Monday, CNET found a few sites still infected with the latest SQL-injection attack.

In the past, attackers have gone after a small niche of the Internet--say travel sites or sports sites--but with this latest attack, attackers have a generic way to blast the Internet, and they've chosen to attack sites running MS-SQL.

On Friday, Microsoft denied that new vulnerabilities within Internet Information Services are to blame for a rash of Web site defacements. Microsoft insists it's the application developer's responsibility to follow the company's best practices. These include constraining and sanitizing input data, using type-safe SQL parameters for data access, and restricting account permissions in the database.

Grossman agreed it's not Microsoft's fault, and said the attacks could have easily targeted another vendor's software. If users surf to an SQL-injected site, their browser will attempt to download a variety of exploits, not all of which are Microsoft-based. One site from the Shadowserver Foundation lists exploits affecting Real and other vendors alongside various Microsoft Security bulletins.

Grossman said that just turning off Javascript won't necessarily protect end users from this latest round of attacks since the attackers can use traditional HTML as well.

"It's said that the attacks never get worse, they only get better," Grossman said. But in terms of the good guys closing the gap with the attackers, he remains optimistic. He said with more diligence and more care, we can protect Web sites from these attacks.

Source: CNet
__________________
Webhosting for Rs12/month!!
http://www.thinkdigit.com/forum/showthread.php?t=74717

http://www.outpowerhosting.com
Cyrus_the_virus is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 29-04-2008, 07:52 PM   #2 (permalink)
Google Bot
 
Pathik's Avatar
 
Join Date: Aug 2005
Posts: 9,772
Default Re: Hundreds of Thousands of Microsoft Web Servers Hacked

Get Apache. Get Secure.
__________________
My new blog: www.pathikshah.com
Pathik is offline  
Old 29-04-2008, 08:05 PM   #3 (permalink)
Wise Old Owl
 
JGuru's Avatar
 
Join Date: Dec 2005
Location: Space-time continuum
Posts: 1,646
Default Re: Hundreds of Thousands of Microsoft Web Servers Hacked

It's business as usual as far as Hackers are concerned!!!!
Use Ubuntu Server Edition with Apache Web Server. It's hack-proof.
No ports are open. Fully secure Linux O.S.
__________________
* Imagination is more important than knowledge.
-Albert Einstein
JGuru is offline  
Old 30-04-2008, 08:23 PM   #4 (permalink)
Right Off the Assembly Line
 
sodhi.bhupinder's Avatar
 
Join Date: Aug 2007
Location: Noida
Posts: 7
Default Re: Hundreds of Thousands of Microsoft Web Servers Hacked

and Hackers are IT professionals working for MNC
__________________
To err is Microsoft ...............
sodhi.bhupinder is offline  
Old 30-04-2008, 08:28 PM   #5 (permalink)
left this forum longback
 
praka123's Avatar
 
Join Date: Sep 2005
Location: -
Posts: 7,536
Smile Re: Hundreds of Thousands of Microsoft Web Servers Hacked

bad reports reg M$haft is sure a headache for window$ users.
Use Linux!move fast!
Debian - http://debian.org -one of the most secure OS.good for server systems.
Ubuntu wont come near Debian Etch when reg,security
__________________
left this forum long back.Admin Can Delete this Account and posts Permanantly.Thank You
Get GNU/Linux - http://getgnulinux.org
praka123 is offline  
Old 30-04-2008, 08:31 PM   #6 (permalink)
!! RecuZant By Birth !!
 
naveen_reloaded's Avatar
 
Join Date: May 2005
Location: In Everyone`s Heart
Posts: 2,985
Default Re: Hundreds of Thousands of Microsoft Web Servers Hacked

sad indeedddd..
__________________
Know My Thoughts..
Visit my Blog @ www.Urssiva.com
Visit My Tech Blog @ www.CloudTechnica.com
naveen_reloaded is offline  
Old 30-04-2008, 09:16 PM   #7 (permalink)
Human Spambot
 
kumarmohit's Avatar
 
Join Date: May 2005
Location: Riding an Oliphaunt
Posts: 2,173
Default Re: Hundreds of Thousands of Microsoft Web Servers Hacked

sad indeed but unless more details emerge and MS is actually held responsible, I think we should go on easy with criticism. Unless we know that it is the road maker's fault, this is like blaming the contractor for losses caused by jaywalkers not following traffic laws and walking on footpath!

If it is actually MS's fault which I strongly suspect is going to be the case, consider the above statement nullified and count me into bashing the company!

@ Praka
Again bro, easy on the links. It makes reading your replies hurt my head and eyes. Too much blue text. Please I humbly state that this forum is not a place to play SEO and improve their page rank!
__________________
The real and only freedom is Public Domain. Everything else in unfree! Even those who claim to be the self styled evangelists of freedom are not free because freedom cannot be forced by any means!
kumarmohit is offline  
Old 30-04-2008, 11:43 PM   #8 (permalink)
Alpha Geek
 
Krazy_About_Technology's Avatar
 
Join Date: Jun 2004
Location: Noida - India
Posts: 765
Default Re: Hundreds of Thousands of Microsoft Web Servers Hacked

I donno the details but if the cause is only sql injection, then no company can be held responsible. Its the responsibility of developers to take measures available to them to strenthen security and i think every book that i have read on database systems and data access technologies talks about these issues, specially SQL Injection.
__________________
Dell Inspiron 1525 - C2D 2 Ghz, 3GB, 250GB, X3100 :)

Samsung Omnia Pro B7610 with Stock WM 6.1 ROM

Blog: http://www.sumitbhardwaj.co.in/blog
Krazy_About_Technology is offline  
Old 30-04-2008, 11:59 PM   #9 (permalink)
The Devil's Advocate
 
iMav's Avatar
 
Join Date: Mar 2006
Location: Masti Ki Paathshaala
Posts: 7,019
Default Re: Hundreds of Thousands of Microsoft Web Servers Hacked

^^ are in any way trying to say that there is a chance that MS's OS are not to be blamed if so then there is no point

you are http://www.thinkantiMS.com/forum
__________________
"The problem that shows up with the three red lights on the console is a complex interaction with some very complex parts.” - Robbie Bach

http://beingmanan.com
twitter: manan | Last.FM: manan
iMav is offline  
Old 01-05-2008, 12:04 AM   #10 (permalink)
BSD init pwns System V
 
hellknight's Avatar
 
Join Date: Sep 2006
Location: atapi.sys as Stuxnet
Posts: 1,230
Default Re: Hundreds of Thousands of Microsoft Web Servers Hacked

Switch to Red Hat Server, Ubuntu Server or Suse Linux Enterprise Server. Make your website secure.
__________________
My blog :- www.openenclave.wordpress.com
hellknight is offline  
Old 01-05-2008, 02:22 AM   #11 (permalink)
Unmountable Boot Volume
 
Cyrus_the_virus's Avatar
 
Join Date: Sep 2007
Location: Kerala
Posts: 907
Default Re: Hundreds of Thousands of Microsoft Web Servers Hacked

Quote:
Originally Posted by Krazy_About_Technology View Post
I donno the details but if the cause is only sql injection, then no company can be held responsible. Its the responsibility of developers to take measures available to them to strenthen security and i think every book that i have read on database systems and data access technologies talks about these issues, specially SQL Injection.
Quote:
Originally Posted by iMav View Post
^^ are in any way trying to say that there is a chance that MS's OS are not to be blamed if so then there is no point
Quote:
Originally Posted by Cyrus_the_Virus
The attackers appear to be breaking into the sites with the help of a security vulnerability in Microsoft's Internet Information Services (IIS) Web servers. In an alert issued last week, Microsoft said it was investigating reports of an unpatched flaw in IIS servers, but at the time it noted that it wasn't aware of anyone trying to exploit that particular weakness.

On Thursday, Spanish anti-virus vendor Panda Security said that it had alerted Microsoft that a flaw IIS was the cause of all the break-ins. When I asked Microsoft whether they'd heard from Panda or if the hundreds of thousands of sites were hacked from a patched or unpatched flaw in IIS, a spokesman for the company didn't offer much more information.

"Microsoft is currently aware of and is receiving reports regarding public claims of attacks on IIS Web servers,"
I wonder which company is to blame for not patching a flaw in MICROSOFT Internet Information Services (IIS)
__________________
Webhosting for Rs12/month!!
http://www.thinkdigit.com/forum/showthread.php?t=74717

http://www.outpowerhosting.com
Cyrus_the_virus is offline  
Old 01-05-2008, 03:00 AM   #12 (permalink)
Alpha Geek
 
Krazy_About_Technology's Avatar
 
Join Date: Jun 2004
Location: Noida - India
Posts: 765
Default Re: Hundreds of Thousands of Microsoft Web Servers Hacked

If thats the case, then plz accept my apologies
__________________
Dell Inspiron 1525 - C2D 2 Ghz, 3GB, 250GB, X3100 :)

Samsung Omnia Pro B7610 with Stock WM 6.1 ROM

Blog: http://www.sumitbhardwaj.co.in/blog
Krazy_About_Technology is offline  
Old 01-05-2008, 12:15 PM   #13 (permalink)
Unmountable Boot Volume
 
Cyrus_the_virus's Avatar
 
Join Date: Sep 2007
Location: Kerala
Posts: 907
Default Re: Hundreds of Thousands of Microsoft Web Servers Hacked

Quote:
Originally Posted by Krazy_About_Technology View Post
If thats the case, then plz accept my apologies
Nothing to apologize about, just showing the facts
__________________
Webhosting for Rs12/month!!
http://www.thinkdigit.com/forum/showthread.php?t=74717

http://www.outpowerhosting.com
Cyrus_the_virus is offline  
Closed Thread

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Mac OS X Hacked - Vista SP1 Hacked – Ubuntu Linux Survives Unscathed CadCrazy Technology News 38 04-04-2008 12:45 PM
lol...Microsoft.co.uk Hacked rajas700 Chit-Chat 2 28-06-2007 01:15 AM
Microsoft admits it doesn't have a fix for exploit in Windows servers eddie Technology News 11 23-04-2007 11:03 AM
Microsoft starting to win over Linux servers anandk Technology News 5 13-04-2007 05:38 AM

 
Latest Threads
- by chris
- by abhidev
- by clmlbx

Advertisement




All times are GMT +5.5. The time now is 05:41 AM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2