Microsoft IIS Under SQL Injection Cyber Attack

By: Bill Waters
Staff Writer
Published: Apr 27, 2008
Over 500,000 Microsoft IIS Web servers are infected less than a day by a flood of SQL injections, leaving pages with malicious iFrames.
According to Panda Security, the number of infected IIS servers reached 282,000, and security firm F-Secure said the number has risen to 500,000 less than a day later.
A flood of SQL injection attacks on Microsoft Internet Information Servers are leaving Web pages with malicious iFrames in them, and Panda Security is urging network managers to make sure their Web pages haven't been infected.
Microsoft IIS administrators can check to see whether their Web pages are infected with the iFrame code by looking for a specific code string in the source code of the Web page associated to an iFrame tag. The string should be eliminated immediately as it adds new malicious code.
Experts say the vulnerability is due in part by poorly-written SQL code that does not properly examine user input from a Web page form.
The exact vulnerability has not been identified, although suspicions center on an April 17 Microsoft Security Advisory (951306) for which there is not yet a defined patch or other fixes.
Malicious iFrame attacks have seen widespread growth over the past several months. Attackers embed the iFrame code in Web pages to redirect victims to sites for purposes of fraud.
Add our Facebook page to receive updates and participate in new tools and features.
Receive daily bite-sized updates by following us at twitter.com/newsoxy.
Subscribe to our daily RSS feed to get the latest national news stories.
- Transformers Serious Injury, Film Actress In Critical Condition
- Melissa Gorga Housewives of New Jersey Cast
- Paris Hilton Wynn Resorts Ban, No More VIP
- New iPod Touch 2010 Adopts Apple Retina
- Guns N' Roses Pelted With Bottles In Dublin
- Harvey Keitel Office Steve Carell Replacement
- Guns N' Roses Pelted At Dublin Concert
- Vermilion Bay Oil Rig Explosion In Gulf of Mexico
- Breaking News: Oil Rig Explodes In Gulf of Mexico
- TI and Tiny Arrested For Methamphetamines, Ecstasy
- Tropical Storm Fiona Projected Path
- Suspected Gunman James Lee Discovery Channel Manifesto
- Apple TV 2010 New iPad Tablet Computing
- Vancouver Acid Attack and Bethany Storro Condition
- Palaeolithic Funeral Feast Unearthed At Burial Site