IIS: more holes than a Swiss cheese

Microsoft releases 10 'urgent' patches

Written by Andy McCue

Multiple 'critical' holes have been discovered in Microsoft's IIS web server that could allow a malicious hacker to remotely gain control of a machine.

Microsoft has released a pack of 10 patches for the holes and is advising users to apply them as a matter of urgency. The flaws range from 'mild' to 'critical' and allow an intruder either to crash or take control of a web server.

Advertisement

The most serious problem concerns a buffer overflow where a hacker could crash a machine with multiple identical repeated commands and then run arbitrary code. IIS versions 4, 5, 5.1 and those in beta test are all vulnerable.

Websites running dynamic active server page scripts on IIS are particularly at risk, the security bulletin said.

But a number of security websites and mailing lists are reporting problems applying the patches, and security experts are warning users to take precautions.

"Install the patch, but be careful because there may be a number of issues, so back everything up first," said Mark Read, network security analyst at MIS Corporate Defence Solutions.

He also advised users to turn off unused functions in IIS. "IIS comes with an awful lot of features, a lot of which are unused, so switch them off, particularly the Internet Server API filter."

Stuart Okin, Microsoft UK's chief security officer, told vnunet.com that the bundling of fixes, and a proactive approach to notifying users, is part of the company's new security processes.

"One of the big demands from customers is if we can roll these patches up, it is easier for them. This is a change in our processes," he said.

"We have mobilised all technical account managers for our enterprise customers, and 10,000 professional and premier IIS customers are being notified. It is part of the evolving process."

Tags:

Related whitepapers

Related jobs

Do you agree?

IT white papers

Search vnunet IThound

Top categories

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Watch

Shaun Nichols and Iain Thomson

03 Oct 2008

6.49 MBPodcast Special: Views from the Valley More...

Podcast image

02 Oct 2008

14.35 MBComputing podcast - Next-generation broadband Britain; and we report from Gartner's IT security summit More...

Shaun Nichols and Iain Thomson

26 Sep 2008

3.43 MBPodcast Special: Views from the Valley More...

Poll

Google Android

Google Android

Are you intending to try out a Google Android mobile phone?

Previous poll results

Spotlight

MoD building

Latest data breach leads MPs to demand culture change

MoD admits to losing a hard drive containing up to...  More...

Online shopping

E-retailers urged to prepare for Christmas

Credit crunch sending shoppers online for cheaper presents   More...

Mobile phone

Emerging markets drive mobile growth

Mobile penetration rates expected to reach 95 per cent by...  More...

Digital information

Poor data classification costing companies dear

Millions wasted on searching through clutter, says analyst   More...

Primary Navigation