Microsoft's IIS 6 Web-server software admits hackers to servers

May 19, 2009 - 7:11am | Fraud | News |
| More
Microsoft's IIS 6 Web-server software admits hackers to servers
It was announced that the vulnerability of Microsoft's Internet Information Services 6 Web-server software that was posted to the Full Disclosure security mailing list by a security researcher Nikolaos Rangos, was being used for online attacks. 

IIS 6 users who have enabled the WebDAV (Web-based Distributed Authoring and Versioning) protocols, used to share documents via the Web were forecasted to be subject to attacks. The attackers using the vulnerability are able to view protected files on the server without authorization. Moreover, they can upload files, states Thierry Zoller, an independent security researcher. 

However, Zoller had found no way to use this flaw to run unauthorized software on an IIS the vulnerability could affect other Microsoft products that use the WebDAV technology. He recommends the users to "Disable WebDAV temporarily and wait for Microsoft to patch."

It is also known that Cisco had warned administrators "to put effective mitigations into place immediately because exploit code is publicly available." 

Microsoft said it was not aware of such attacks.





RSS feed Subscribe to Ecommerce Journal RSS feed

0 points

   Tell us what topics you want to be covered in the Ecommerce Journal?  
Image CAPTCHA
  


Comments on Microsoft's IIS 6 Web-server software admits hackers to servers

Post new comment

CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.
Image CAPTCHA
Copy the characters (respecting upper/lower case) from the image.



Similar Articles on Ecommerce Journal by sections

FIGURES
PAYMENT SYSTEMS
BANKS
PLASTIC CARDS
ECOMMERCE-CHECKED
INVESTMENT INDUSTRY
FRAUD
ANALYTICS
OTHER THEMES
INTERVIEWS
LAW ASPECTS