IIS present vulnerability foreign tens of thousands of servers are under attack

Source: Internet
Author: User
Keywords IIS attacks servers Microsoft

According to the http://www.aliyun.com/zixun/aggregation/4585.html > Washington Post, tens of thousands of Web sites have recently been hacked and hung by horses. These sites include even some sites from UN and UK government. It is most likely that an attacker is entering the site with IIS vulnerabilities. Last week Ms released a security warning about a new vulnerability that has not been fixed in IIS. But Microsoft has not found anyone exploiting the flaw.

The Thursday Panda Company warned Microsoft that the intrusions were caused by an IIS vulnerability. The Post reporter asked Microsoft about the situation and did not respond positively. Microsoft has received reports about the attack but has not yet confirmed that the attack is relevant to the recently released security Warning and is ready to further observe the confirmation. Finland's F company estimates that the number of hacked Web pages caused by this attack is nearly 50 million.

An independent security analyst revealed that the infected page would be appended with JavaScript code, which would be secretly nihaorr1.com and haoliuliang.net from the domain name of the Chinese domain when the user browsed. Download malware.

But the post-news reader replied that there was no IIS vulnerabilities, just a tool that uses Google to automatically search for and exploit Microsoft's SQL vulnerabilities. People may be mistaken for a new IIS vulnerability but are actually using web Developer code design negligence.

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.