Experts agree on method, not scope of IIS attacks
IDG News Service -
One day after reports of Web site attacks surfaced, there was disagreement about how widespread the attacks were and how many Internet users were affected by them.
Security experts on Friday said companies that failed to apply a recent software patch for Microsoft Corp.'s Internet Information Services (IIS) Version 5.0 Web server were vulnerable to a new Web-based attack from an online criminal hacking group, while Microsoft acknowledged that even individuals running the latest patches for IIS and the Internet Explorer Web browser could be affected if they didn't make additional configuration changes. But there were widely different accounts of the attacks' impact on companies and Internet users.
Hackers are using a recently patched hole buffer overflow vulnerability in Microsoft's implementation of SSL (Secure Sockets Layer) to compromise vulnerable Windows 2000 systems running IIS, Microsoft's Web server, said Stephen Toulouse, security program manager in Microsoft's Security Response Center.
Microsoft patched that flaw in April when it released Security Bulletin MS04-011, so companies that installed the patch were not vulnerable to compromise, and attackers did not use an unknown or "zero day" hole to compromise IIS, he said.
However, the story is more complicated for Internet users and Web surfers. The recent attacks used two vulnerabilities in Windows and the Internet Explorer Web browser to silently run the malicious code on machines that visited the compromised sites, redirecting the customers to Web sites controlled by the hackers and downloading a Trojan horse program that captures keystrokes and personal data, he said.
One of those vulnerabilities was in code for Microsoft's Outlook Express e-mail client that interpreted a kind of URL known as a MIME Encapsulation of Aggregate HTML, or MHTML URL, which allows documents with MHTML-encoded content to be displayed in software applications like the Internet Explorer Web browser. That vulnerability was addressed in a security patch from Microsoft, MS04-013, also released in April, he said.
The second vulnerability was discovered last week and Microsoft doesn't have a patch for it, Toulouse said. That hole, called a "cross zone scripting" vulnerability, allows attackers to trick Internet Explorer into loading insecure content using relaxed security precautions typically applied to files stored on the local hard drive or obtained from a trusted Web site such as www.microsoft.com, according to experts.
Even Internet Explorer users who apply the MS04-013 patch could still be compromised, Toulouse said. Only setting the Internet Explorer security level to "high," and having up-to-date antivirus software to spot the Trojan horse program as it is downloaded can prevent infection, he
Reprinted with permission from
Story copyright 2009 International Data Group. All rights reserved.
Viruses
Additional Resources



Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.
White Papers & Webcasts
Share our Strength
Download Now
Key Strategies for Managing Data Growth
What are you storage challenges?
Can Heuristic Technology Help Your Company Fight Viruses?
What is Heuristic Technology and how can it help safeguard your business against viruses? Learn more.
Extending Client Refresh - 11 Steps to Maximize Savings
Register Now!
Eradicate Spam & Gain 100% Asurance of Clean Mailboxes
Get this paper now!
Lower the Cost and Complexity of a Mobile Workforce through Automation
Download This Resource Now!
Mastering eDiscovery: The IT Manager's Guide to Preservation, Protection & Production
Get this paper now!
Managing Mobility: Improve Data Security, Compliance and Manageability
Download This Resource Now!
Not Just Words: Enforce Your Email and Web Acceptable Usage Policies
Get this paper now!
Consolidate Your Servers and Storage to Lower Costs with Oracle Database 11g
Register for this webcast!
