eSecurity Planet   Earthweb  
Images Events Jobs Premium Services Media Kit Network Map E-mail Offers Vendor Solutions Webcasts
   eSecurity subjects:
E-Security Planet Webcasts:
Keeping Your Data Secure from the Outside In

Beyond Basic Data Security

more Webcasts...


Search EarthWeb Network

internet.commerce
Be a Commerce Partner
Remote Online Backup
Corporate Awards
Rackmount LCD Monitor
Web Design
Compare Prices
Domain registration
Promote Your Website
GPS
Cell Phones
Car Donations
Computer Hardware
Imprinted Gifts
Shop Online
Compare Prices

esecurityplanet: Half-Million IIS Servers Hit in Cyber Attack

Download: SQL Backup & DBA Best Practices eBook. Future Proof Your DBA Career and make the most of your office hours. Get this download now to learn how.
  Generate Revenue Through IT Using Business Service Management
Sponsored by HP
Making sure that your business applications are available to their end users is an important part of running your business smoothly. Business operations have evolved to where IT must now broaden its focus to help the company attract, retain and grow customer relationships and increase customer satisfaction. Business service management (BSM) helps lay the foundation by managing services in dynamic support of business requirements. »
 
  Managing the Modern Network
Sponsored by HP
Networks are more than vehicles to transport e-mail and Web pages. In a global economy where information crosses the globe in an instant, and where Web-based applications power business, it's more important than ever to ensure your network is safe from threats and optimized to deliver the data your business needs. »
 
  Storage Networking 2, Configuration and Planning
Sponsored by HP
In Part 1, we discussed storage area networks (SANs) and fibre channel. In Part 2, delve into best practices and cover the general concepts you must know before configuring SAN-attached storage. The most critical, sometimes tedious, part of setting up a SAN is configuring each individual disk array. This guide examines configurations for SAN-attached servers and disk arrays, and also includes a look at the future of IP storage. »
 
  Is Your Disaster Recovery Plan Good Enough? Get Disaster Recovery Right
Sponsored by HP
Preparing for a disaster is more often than not part of the storage planning process, and without question it is one of the most difficult task, since it includes local hardware and software, networking equipment, and a test plan to ensure that you can recover from the disaster. Learn how to put your organization on the proper disaster recovery plan, now. »
 

Access FREE HP High-Availability Solutions for Exchange 2007 Tools:
Access FREE HP Server Solutions Tools:
Whitepaper:
Backup and Recovery Best Practices for Microsoft Exchange Server 2007 with HP

Whitepaper:
Best Practices for HP Servers and HP Enterprise Virtual Array in a Microsoft Exchange

Whitepaper:
Optimizing HP Servers with Microsoft SQL Server 2008

Whitepaper:
Backup and Recovery Best Practices for SQL Server 2005

Whitepaper:
Configuration Best Practices for Microsoft SQL Server 2005 with HP EVA4000 and HP Blade Servers

Related Articles
Web 2.0 in Enterprise Needs a Lock
March of The Trojans
Begging to be Spammed
eSecurity Glossary
biometrics
encryption
keylogger
malware
phishing
RFID
security
spyware
virus
worm
Search for more eSecurity terms ...
FREE Tech Newsletters

Half-Million IIS Servers Hit in Cyber Attack
April 25, 2008
By Andy Patrizio

A massive cyberattack is targeting vulnerable Internet Information Server-based Web pages by redirecting visitors to the site toward one hosting malicious code, and it's growing rapidly.

When Panda Security first noted the infestation, it put the number of infected IIS servers at 282,000. Not even a day later and security firm F-Secure wrote its own blog entry, putting the infestation at over 500,000.

The worst part of it all is that these infestations are not in seamy Web sites, they are taking place in legitimate Web pages. An IFRAME (define) redirects the user to another page, where identity-stealing malware is downloaded onto their computer. So even users who think they are staying clean are not safe.

"In the old days, you used to think if you went to the dark side of the Internet you had a chance of being infected. Now you don't need to go to the bad neighborhoods to get attacked. You can be walking down the good side of the Internet and be infected," said Ryan Sherstobitoff, chief corporate evangelist at Panda Security.

The vulnerability in IIS, developed by Microsoft (NASDAQ: MSFT), allows hackers to inject SQL code to manipulate legitimate Web pages. This code adds an IFRAME to redirect the user to a malicious Website that scans their computer for vulnerabilities and then downloads and installs malware that can get passed the user's defenses.

The problem only affects IIS, not Apache or other Web servers. Microsoft reportedly knows of the issue, said Sherstobitoff. The company has not responded to a query InternetNews.com on when a fix can be expected as of press time.

Sherstobitoff said the U.S. is being hardest hit, with government and public utility sites particularly popular. "They love anything that brings in victims," he said.

Panda and F-Secure both identified a malicious piece of code being hidden in Web pages that does the redirect. Site admins should look for this hidden in their Web pages:

<script src=http://www.nihaorr1.com/1.js>

If that appears anywhere in the page, then you have a problem, as some people have noticed. Securing the server, updating all of the patches and proper configuration should help protect it until Microsoft comes out with a fix of its own, said Sherstobitoff.

This article was first published on InternetNews.com.

 

Tools:
Add www.esecurityplanet.com to your favorites
Add www.esecurityplanet.com to your browser search box
IE 7 | Firefox 2.0 | Firefox 1.5.x
Receive news via our XML/RSS feed

esecurityplanet Archives

eBook: Evaluating Software as a Service for Your Business. Sponsored by Webroot
Learn about expanding business opportunities for the reseller channel. Visit IT Channel Planet.
Five Trends for Application Development. Download Your Complimentary Report. Exclusive. Act Now.
Keep up with the latest business and technology news and information! Visit Internet.com.
Whitepaper: Enterprise Information Integration--Deployment Best Practices for Low-Cost Implementation



JupiterOnlineMedia

internet.comearthweb.comDevx.commediabistro.comGraphics.com

Search:

Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

Jupitermedia Corporate Info


Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers

Solutions
Whitepapers and eBooks
Microsoft Article: HyperV-The Killer Feature in WinServer ‘08
Avaya Article: How to Feed Data into the Avaya Event Processor
Microsoft Article: Install What You Need with Win Server ‘08
HP eBook: Putting the Green into IT
Whitepaper: HP Integrated Citrix XenServer for HP ProLiant Servers
Intel Go Parallel Portal: Interview with C++ Guru Herb Sutter, Part 1
Intel Go Parallel Portal: Interview with C++ Guru Herb Sutter, Part 2--The Future of Concurrency
Avaya Article: Setting Up a SIP A/S Development Environment
IBM Article: How Cool Is Your Data Center?
Microsoft Article: Managing Virtual Machines with Microsoft System Center
HP eBook: Storage Networking , Part 1
Microsoft Article: Solving Data Center Complexity with Microsoft System Center Configuration Manager 2007
MORE WHITEPAPERS, EBOOKS, AND ARTICLES
Webcasts
Intel Video: Are Multi-core Processors Here to Stay?
On-Demand Webcast: Five Virtualization Trends to Watch
HP Video: Page Cost Calculator
Intel Video: APIs for Parallel Programming
HP Webcast: Storage Is Changing Fast - Be Ready or Be Left Behind
Microsoft Silverlight Video: Creating Fading Controls with Expression Design and Expression Blend 2
MORE WEBCASTS, PODCASTS, AND VIDEOS
Downloads and eKits
Sun Download: Solaris 8 Migration Assistant
Sybase Download: SQL Anywhere Developer Edition
Red Gate Download: SQL Backup Pro and free DBA Best Practices eBook
Red Gate Download: SQL Compare Pro 6
Iron Speed Designer Application Generator
MORE DOWNLOADS, EKITS, AND FREE TRIALS
Tutorials and Demos
How-to-Article: Preparing for Hyper-Threading Technology and Dual Core Technology
eTouch PDF: Conquering the Tyranny of E-Mail and Word Processors
IBM Article: Collaborating in the High-Performance Workplace
HP Demo: StorageWorks EVA4400
Intel Featured Algorhythm: Intel Threading Building Blocks--The Pipeline Class
Microsoft How-to Article: Get Going with Silverlight and Windows Live
MORE TUTORIALS, DEMOS AND STEP-BY-STEP GUIDES