virtualreview

tech: news and opinion

IIS bug gives attackers complete server control

Linux and Chrome flaws too A hacker has uncovered a previously unknown bug in Microsoft's Internet Information Services webserver that in some cases gives attackers complete control of vulnerable machines.…Web threats: Why conventional protection doesn... ...full story at the register (uk)

from the register (uk) on Mon, Aug 31 2009

see also:

02 Sep 09 visit Microsoft confirms IIS bug gives complete server control  »  the register (uk) But only if ... Microsoft has confirmed a vulnerability in its Internet Information Services webserver and spelled out the conditions under which it can be exploited to give an attacker complete control of the server on which it runs.…Web threats: W...
25 Dec 09 visit Microsoft IIS vuln leaves users open to remote attack  »  the register (uk) Beware of the 'semicolon bug' A researcher has identified a vulnerability in the most recent version of Microsoft's Internet Information Services that allows attackers to execute malicious code on machines running the popular webserver.…Web threats: W...
04 Sep 09 visit New IIS attacks (greatly) expand number of vulnerable servers  »  the register (uk) Microsoft's webserver even easier to exploit Attackers have begun actively targeting an unpatched hole in Microsoft's Internet Information Services webserver using new exploit code that greatly expands the number of systems that are vulnerable to the...
03 Nov 09 visit Bug in latest Linux gives untrusted users root access  »  the register (uk) Protections for some, but not all A software developer has uncovered a bug in most versions of Linux that could allow untrusted users to gain complete control over the open-source operating system.…Web threats: Why conventional protection doesn't work
18 Aug 09 visit Adobe patches 'critical' flaws in ColdFusion, JRun  »  the register (uk) Code execution, information disclosure bugs dead Adobe Systems has released updates that patch vulnerabilities in two widely used web development applications, several of which let attackers steal sensitive data or take complete control of users'...

« Today's Stories