Hundreds of thousands of Microsoft web servers hacked; including government servers

“Hundreds of thousands of Web sites – including several at the United Nations and in the U.K. government — have been hacked recently and seeded with code that tries to exploit security flaws in Microsoft Windows to install malicious software on visitors’ machines,” Brian Krebs reports for The Washington Post.

“The attackers appear to be breaking into the sites with the help of a security vulnerability in Microsoft’s Internet Information Services (IIS) Web servers,” Krebs reports.

“On Thursday, Spanish anti-virus vendor Panda Security said that it had alerted Microsoft that a flaw IIS was the cause of all the break-ins. When I asked Microsoft whether they’d heard from Panda or if the hundreds of thousands of sites were hacked from a patched or unpatched flaw in IIS, a spokesman for the company didn’t offer much more information,” Krebs reports.

“‘Microsoft is currently aware of and is receiving reports regarding public claims of attacks on IIS Web servers,’ said Bill Sisk, a security response manager at Microsoft, in a statement e-mailed to Security Fix. ‘While we have not be [sic] contacted directly regarding these reports, we will continue to monitor all reports either publically [sic] shared or responsibly disclosed and investigate once sufficient details are provided. We have not yet determined whether or not these reports are related to Microsoft Security Advisory (951306) released last week,'” Krebs reports.

“According to Finnish anti-virus maker F-Secure, the number of hacked Web pages serving up malicious software from this attack may be closer to half a million,” Krebs reports.

Full article here.

[Thanks to MacDailyNews Reader “RadDoc” for the heads up.]

MacDailyNews Take: UNIX 03 compliance, cross-platform capabilities, and no client-access licenses make Mac OS X Server v10.5 Leopard a rock-solid network foundation. Mac OS X Server v10.5 Leopard brings its enhanced multicore performance, astounding system improvements, and powerful new features to Xserve. Now you can easily set up and manage servers, add new clients to the network, share calendars, schedule meetings, and more. Leopard Server is built on a fully compliant UNIX foundation. This rock-solid core provides the stability, performance, and security that organizations require — and full UNIX conformance ensures compatibility with existing server and application software. An Open Brand UNIX 03 Registered Product, Mac OS X Server can compile and run all your existing UNIX code. So you can deploy it in environments that demand full conformance, complete with hooks to maintain compatibility with existing software. With out-of-the-box support for Mac, Windows, UNIX, and Linux clients, Xserve is the easiest way to provide powerful, innovative network and Internet services for multiplatform workgroups. And there are no client-access licenses, which means no extra fees. Leopard Server supports 64-bit addressing and large LUNs without requiring you to buy a special enterprise version. Buy Xserve with Mac OS X Server v10.5 Leopard Unlimited-Client Edition for just $2,999.

41 Comments

  1. My support for Apple products has never been questioned or attacked, so I’ll say that it makes no sense to revel in the misfortune of MS. So how is it that disparaging MS, Bill Gates, or Baldy Balmer make Apple any better for the effort?

    That’s my 2 pennies worth.

  2. […] ‘While we have not be [sic] contacted directly regarding these reports, we will continue to monitor all reports either publically [sic] shared or responsibly disclosed […]’

    For a brief horrifying moment I afraid that second “sic” typo was because the text read “we will continue to monitor all reports either pubically shared” – clearly, the story about the returned Dell laptop still lingers in the dark recesses of my mind…

  3. You know, these IT people need re-educating. Why would you use a M$ server in the first place? It’s always wide open to attacks. Not only is Mac OS X Leopard Server far more secure, it’s also easier to deploy and has far more features.

  4. There goes all that passion and potential out the window once a gain. One of the definitions for insanity is the expectation that you can do the same things over and over again yet expect different results.

  5. Hundreds of thousands!! Hundreds of thousands!! Hundreds of thousands!! Hundreds of thousands!! Hundreds of thousands!! Hundreds of thousands!! Hundreds of thousands!! Hundreds of thousands!! Hundreds of thousands!! Hundreds of thousands!!

  6. If your company relies on M$ servers then you might as well close the business down.

    Don’t be absurd. The threat isn’t Microsoft, it’s the insurance industry.

    However, if your company relies on government cheese, then you might as well close the business down cause you’ll be caught standing when the music stops; a great culling of the market place is forthcoming.

    Keep your eye on the insurance industry though. There is a shitty little business arm of the industry, who are like scavengers that come in after the carnage to initiate damage control and preserve what’s left.

    Some of these companies hire unscrupulous IT who can sift through a company’s data like tea leaves from which emerges a highly-accurate picture of not only the health of your company, but your employees too. Insurance companies see it as a proactive measure to protect their investment.

    Think about it. The insurance industry is in bed with the medical industry and together they have access to just about every intimate aspect of this nations deepest, darkest secrets.

    If an insurance company wanted to cull a company from the pack they need only find an area on the grid that is the weakest link. In this case it’s the IIS web servers.

    Microsoft gets blamed in the press and the insurance industry recedes quietly back into the background.

    Cue the organ music… curtain… house lights…

    ” width=”19″ height=”19″ alt=”LOL” style=”border:0;” />

  7. nice work dualie.

    (someone on here was supposed to send me directions to the pre-rev meet up., oh well, i’m sure i’ll be present and accounted for, with left-hand raised high, when the time comes.)

  8. nah, this can’t be true, cause i read the windows news headline “Windows 2003 Hacked Less Often Than Linux”

    heck they say in 7 years windows was hacked .8 million times. this article says .5 million in two weeks……

    that is some curve!

  9. Here’s a clue that just fucking hit me the other day and I am baffled why I never thought of the current situation this way.

    Why, exactly, does any Microsoft Windows house pay a per user fee? Why? You’ve already paid that fee by having to have a legit copy of windows on every single box already in your organisation! How did corporate Amercica fall for this outright scam in such a huge way? What kind of idiots are running corporate America that this near criminal situation was allowed to flourish?

    But then one only has to look at the current mortgage crisis meltdown to realise that too many people in positions of power got there thru luck, not necessarily brains or hard work.

  10. OS X Server is not without its share of flaws. Some of them are VERY serious. For example the VPN service in 10.4.11 will eventually bring down the whole server. 10.5.2 has even more problems, just have a look at the support forums. No need to hype OS X Server, maybe at 10.5.10 it will be stable and bugfree enough to be taken seriously. No bashing intended, I am just disappointed with OS X Server. The desktop OS X on the other hand is much better.

  11. Comment from: G4Dualie 
    If your company relies on M$ servers then you might as well close the business down.

Don’t be absurd. The threat isn’t Microsoft, it’s the insurance industry.
    ————————————
    I can’t disagree more …

  12. While Mac Mini might be a more secure server than an IIS (regardless of hardware), it is foolish to recommend a Mac Mini as a server. I’m sure DavidBaker meant that as a slight exaggeration; for those who took it seriously, please, don’t do that. If you’re building a server, spend an extra two grand and get a Mac Pro. Mac Mini has a laptop hard drive. It is in fact a screenless laptop. It would be extremely shortsighted to expect Mini to be able to endure the pounding an average server gets. Get a refurbished Mac Pro (or X-serve) and you have the best, cheapest, most reliable server machine there is.

  13. If you really want to hack a server, I mean really wanna get into it, for corporate sabotage… you only need to keep trying.

    OSX servers just haven’t been around long enough and been in the right places for someone to pay enough to commit corporate sabotage. Put 1/2 million of them out there in large corporations and let’s see how they do.

    The only reason why suits use Microsoft and shitty PCs is they don’t know any better. IT people have jobs because of the Microsoft PC. A whole micro-industry is based on keeping up with a dinosaur OS that people are afraid of leaving. How many companies are out there that just offer spyware and virus software. Supporting the Microsoft way of life is a multi billion dollar business. It will die hard people.

    This is why people will spend whatever Microsoft says they will spend, and do what Microsoft says to do. After all, they are in the business of business, not computers or software.

    – Pi has spoken

  14. “Nowadays, security guys break the Mac every single day. Every single day, they come out with a total exploit, your machine can be taken over totally. I dare anybody to do that once a month on the Windows machine.”
    – Bill Gates

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.