Microsoft reports attacks using IIS vulnerability
~Lordbob
Microsoft reports attacks using IIS vulnerability | Deep Tech - CNET NewsA vulnerability in Microsoft's software for housing Web sites is now being used for "limited attacks" on the servers it's running on, the company said Friday.
Microsoft disclosed the Internet Information Services (IIS) vulnerability on Monday and said Friday it's still working on a security update to fix the problem. In the meantime, the advisory has instructions for a workaround, including disabling various elements of the vulnerable FTP (File Transfer Protocol) service to upload and download files.
According to the advisory, the vulnerability could let somebody run arbitrary code on a server using FTP on IIS 5.0 and conduct a denial-of-service attack using FTP on IIS 5.1, 6.0, and 7.0. The present version 7.5 isn't affected, though, and FTP 7.5 can be downloaded and installed on IIS 7.0 to protect it.
"Customers should be aware that the Download Center has FTP 7.5 available for Windows Vista and Windows Server 2008. FTP 7.5 is not vulnerable to any of these exploits," said Alan Wallace, senior communications manager for Microsoft's security response communications team, in a statement.
Initially, the company said it was investigating a vulnerability only with versions 5 and 6 of IIS.
~Lordbob
My Computer
- Computer Manufacturer/Model Number
- Hera
- OS
- Windows 7 Ultimate x64, Mint 9
- CPU
- Intel i5-2500k
- Motherboard
- ASUS P8P67 Pro
- Memory
- 2x 4Gb Corsair VENGEANCE DDR3-1600
- Graphics Card(s)
- NVidia GeForce N260GTX Twin Frozr
- Sound Card
- Realtek HD OnBoard Audio
- Monitor(s) Displays
- ASUS 24" Monitor
- Screen Resolution
- 1920x1080
- Hard Drives
- G.SKILL Phoenix Series 60GB SATA II MLC Internal Solid State Drive (SSD)
SAMSUNG Spinpoint F3R 1TB 7200 RPM 32MB Cache SATA II
- PSU
- Cooler Master Real Power Pro 750W
- Case
- Cooler Master Haf 932
- Cooling
- Fans
- Keyboard
- Razer Tarantula
- Mouse
- Razer Lachesis
- Internet Speed
- not fast enough