Microsoft denies that server hacks are its fault

The large scale infection of Internet servers mentioned Friday has been attributed by Panda Security to flaws in Microsoft server software. The Washington Post reported:

Hundreds of thousands of Web sites - including several at the United Nations and in the U.K. government — have been hacked recently and seeded with code that tries to exploit security flaws in Microsoft Windows to install malicious software on visitors’ machines.

The attackers appear to be breaking into the sites with the help of a security vulnerability in Microsoft’s Internet Information Services (IIS) Web servers. In an alert issued last week, Microsoft said it was investigating reports of an unpatched flaw in IIS servers, but at the time it noted that it wasn’t aware of anyone trying to exploit that particular weakness.

Microsoft has denied that its software is at fault. According to Computerworld:

Microsoft Corp. late Friday denied that vulnerabilities in its Web and SQL Server software had been exploited to hack hundreds of thousands of Internet pages.

Did you enjoy this post? Why not leave a comment below and continue the conversation, or subscribe to my feed and get articles like this delivered automatically to your feed reader.

Comments

No comments yet.

Sorry, the comment form is closed at this time.