Half A Million Microsoft-Powered Sites Hit With SQL Injection

post<li>

A new SQL injection attack aimed at Microsoft IIS web servers has hit some 500,000 websites, including the United Nations, UK Government sites and the U.S. Department of Homeland Security. While the attack is not Microsoft’s fault, it is unique to the company’s IIS server.

Webcomic The automated attack takes advantage to the fact that Microsoft’s IIS servers allow generic commands that don’t require specific table-level arguments. However, the vulnerability is the result of poor data handling by the sites’ creators, rather than a specific Microsoft flaw …

Read More Via: http://blog.wired.com/

Tags: , , , , ,

POSTA UN COMMENTO

La Tua email non sarà pubblicata ne diffusa. Campi modulo necessari *

*
*

SPONSOR

VIDEO TUTORIAL

TAG CLOUD