Microsoft Responsable for Mass Hack?
Microsoft Responsable for Mass Hack?

Internet security is a very relative and, apparently, vulnerable thing. Every little flaw will be taken advantage of. According to Finnish anti-virus maker F-Secure, more than 500,000 websites, including several hosted by the United Nations and the U.K. government, have recently been hacked and modified in order to download malware to visitors’ computers.

Although this was denied by company officials, it seems that the hackers made use of vulnerabilities in Microsoft’s Web and SQL server software. Bill Sisk, a communications manager with the Microsoft Security Response Center, feels otherwise: "[They] are not issues related to IIS 6.0, ASP, ASP.Net or Microsoft SQL technologies," says a note found on the group's blog.

On Friday, Spanish anti-virus developer Panda Security said that it had informed Microsoft on the "security issue" it had detected in the company's Internet Information Services (IIS).

Security analyst Dancho Danchev gave site owners some advice as to how they can tell whether or not their websites have been modified by the attack. According to him, a distinctive mark of hacked sites is that they seem to have Javascript coding added to the page source, which brings about malware from several domains in China, such as nihaorr1.com and haoliuliang.net.

There is however a solution to this problem, as some recommend the use of Firefox instead of Internet Explorer. Firefox features an add-on called "noscript," which doesn’t allow Javascript exploits to run automatically when a hacked site is visited.




© 2007 - 2009 - eNews 2.0 All Rights Reserved
 
 
"responsAble"
By Tom, (2008-04-28 12:54)
I see it all the time - that is tech journalist who haven't discovered the wonders of a spell checker.

Hell, my Opera browser comes standard with a great spell checker, so there's absolutely no excuse.
Journalists responsAble for a society that can't spell?
By anonymous, (2008-04-28 02:41)
Give me a frickin' break.
 
 



 

dotclear
dotclear