WHIR | BLOGS | WEB HOST NEWS | FIND WEB HOSTS | RESELLER HOSTING | MAGAZINE | WHIR TV | NEWSLETTER | rss feeds
web hosting news - daily web host interviews, insight Jobs | Events | Sitemap | Search
Green Data Center Info


WEB HOSTING NEWS | BLOGS | INTERVIEWS | EUROPE | EVENTS | WEB HOSTING JOBS

<< Hostopia to Acquire uplinkearth     CashEdge Deploys Ensim Unify >>


Microsoft Says Attacks Not its Fault

April 28, 2008 -- (WEB HOST INDUSTRY REVIEW) -- In a Friday evening blog posting, Microsoft (microsoft.com) denied reports that a vulnerability in its SQL server software had enabled hundreds of thousands of websites to be infected with malicious code last week.

   
Why use a vendor when you can choose a partner? DataPipe delivers highly customized solutions to meet your unique IT needs. World-class data centers in the U.S., London & China. DataPipe - Personal Touch, Global Reach.

"Our investigation has shown that there are no new or unknown vulnerabilities being exploited. This wave is not a result of a vulnerability in Internet Information Services or Microsoft SQL Server," said Bill Sisk of The Microsoft Security Response Center in a 9:44 p.m. post to that organization's blog.

It was widely reported on Friday that more than 500,000 webistes, including some belonging to organizations such as the US Department of Homeland Security and the United Nations, had been hacked. Many of those stories suggested that a vulnerability in Microsoft's SQL server software might be at fault.

Panda Security said Friday that it had notified Microsoft of a "security issue" in Internet Information Services, though the organization did not specifically call the problem a "vulnerability."

According to Sisk, the attack is not an exploit related to any known or unknown vulnerabilities in any Microsoft software, but is instead a more common SQL injection attack, which "enable malicious users to execute commands in an application's database." He says website or application developers can protect against such attacks by using security procedures outlined in its developer network library.

A post on Microsoft's IIS blog further explained that the attack was not associated with a software vulnerability, and recommended that end-users update their security with the latest patches to protect themselves from being impacted by the attacks.

In a Friday article, the Register quoted security experts who said the task of deleting malicious code from affected sites was going to be enormous and would likely take a very long time, as developers replaced overwritten records or reverted sites to recent backups.

Print this Page       Email this Page        Add to: | del.icio.us | digg


COMMENTS

Be the first one to comment on this article. Click the link below to post your comment.

[POST COMMENT]



Q&A: Dennis Quan, IBM

Q&A: Jonathan Bryce, Mosso

Q&A: Nick Nelson, UK-2/Dotable

1&1 Opens Lenexa Data Center

Noise Filter: Ky. Domain Seizure

NaviSite Launches Dedicated Hosting

Q&A: Michael van Dijken, Microsoft

More feature interviews and reports
 

Doing a deal at a Fire Sale Read My Alpha Red

Fear - Reading Alpha Red

Dedicated Hosting Prospects and Their Clues

WHIR Mag, Oct. 08: Big Money

WHIR Magazine for your iPhone

Hosting Transformation Summit 2008 - Video Feedback

More posts from our Bloggers


ReliableSite Offers Clustered Hosting

Cartika Offers Linux Cloud Hosting

Cirrus Tech Adds Exchange, SharePoint

Spam Activity Drops After ISP's Demise

CM4all Helps Hostpoint Add Languages

Chelsey Consulting Buys ICNS

Internode Powered By Renewables

The Web Host Industry Week in Review

FatCow 'Goes Pink' for Breast Cancer

CWIE Out, Alpha Red Done?

UK2.net Turns 10, Offers 10% Discount

DRT, IBM Open Green Paris Facility


 

Office Administrator

Senior Windows System Engineer

Programmer Analyst

Group Marketing Manager

Network Operations Engineer

Technical Customer Care Representative

National Account Manager

Customer Service Representative

Legal Assistant (Part-Time)

Project Manager

 

SPONSORED LINKS
> Apollo Hosting: Award Winning Website Hosting from $6.96 – Click Here!

> iWeb: Quality servers. 3000GB of traffic for only $69

> TopLayer: SC Mag Recommended. Protect against DDoS Attacks & more.

> Parallels: Automation and Virtualization. Buy ONLINE or Learn MORE!

> Website Source: Powerful Website hosting starting at $6.85

> Rackspace: What Do You Get With Your Hosting Provider?

> PEER 1: World-class managed hosting. ValuePro Plan just $299.

> Click here for special deals and offers from WHIR sponsors!

> Click here to learn more about going green with your data center

> Is your company hiring? Post your job listing here!

WHIR NEWSLETTER SIGN-UP | MANAGE SUBSCRIPTIONS | WHIR RSS FEEDS
Name:
Email:
Password:
theWHIR Blog Email Update
Magazine
Daily News
Find Web Hosts
Occupation:
Company Type:

Find Web Hosts | Reseller Hosting | Personal Web Hosting | Small Business Web Hosting | Dedicated Servers | Managed Hosting | Adult Web Hosting


About WHIR | Online Advertising | Print Advertising | Print Subscription | Email Newsletters | RSS Feeds
 
Submit News | Privacy Policy | Buy Reprints

Web Host Industry Review, Inc. is not responsible for the content of comments submitted by our users.

  © Copyright Web Host Industry Review, Inc.