posted by Thom Holwerda on Mon 28th Apr 2008 19:22 UTC, submitted by Hakime
In an entry on Microsoft's IIS Blog, Bill Staples explains that despite earlier reports online, the attacks are not related to Security Advisory 951306 or any other security flaw in Microsoft's IIS 6.0, ASP, ASP.Net or Microsoft SQL technologies. Instead, the crackers used automated SQL injection attacks.
Instead, attackers have crafted an automated attack that can take advantage of SQL injection vulnerabilities in web pages that do not follow security best practices for web application development. While these particular attacks are targeting sites hosted on IIS web servers, SQL injection vulnerabilities may exist on sites hosted on any platform.
Staples links to various websites that give more information on SQL injection attacks, and how to shield yourself from them. In addition, the IIS.net website follows the issue and provides more information as the case develops.
Microsoft's investigation revealed no unpatched security holes in IIS, SQL Server, Internet Explorer or any other Microsoft client software, so end-users should just install all the latest patches to shield themselves from these attacks.
Related Articles
posted by Amjith Ramanujam on Mon 21st Jul 2008 14:35, submitted by Thom_Holwerda
posted by Amjith Ramanujam on Fri 18th Jul 2008 23:29 submitted by Dale Smoker
posted by Amjith Ramanujam on Tue 15th Jul 2008 17:45, submitted by Thom_Holwerda


