johnhendron.net: hendron’s digest - a weblog

This is Hendron’s Digest, a weblog devoted to the intersection of education & technology.

Microsoft IIS Hacked

Wow. This is significant.

Microsoft’s IIS servers have been hacked, sending malicious code to you through your browser, if you visit an affected website.

This report says perhaps over .5 million web servers have been compromised.

johnhendron.net uses the Apache web server.

5 Responses to “Microsoft IIS Hacked”

  1. Jim Says:

    Yep, I use apache as well. Haven’t had an issues in the last 8 years with apache. Heck, I dont think I’ve even rebooted it sense. Then.

    What version of Apache / OS you use?

  2. John Says:

    I believe this site is hosted on Debian Linux with Apache 2.

    The web server I manage at work is currently at 1.3 for apache on OS X Tiger server. I think with OS X Leopard server, you jump up to Apache 2 by default.

  3. M.W. Says:

    The OS of the server will not protect you from this sort of code injection. This hack is created by poor website development, not a crack in MS’s IIS.

  4. John Says:

    I don’t know M.W.; it seems only the OS from one manufacturer is listed here.

    While the article suggests it’s a IIS issue; yes, commenters on the story I linked to–at least some–feel otherwise.

    If 500,000 web servers “overnight” contain the tell-tale code described in the report, and they are all websites served by IIS, then it would be silly to suggest it’s just poor coding by web developers. It would raise the question of why they would want to develop on a platform that made this exploit possible.

  5. Jim Says:

    M.W. does have a point. I’ve seen plenty of websites hacked from SQL injection. Basically its putting SQL in the form inputs on the pages.

    The input from say, even this text box I am typing in, could possibly accept some sort of injection code, whether it be SQL, PHP or something else.

    Still, you have to wonder……500K+ IIS Servers? Does this mean that all 500K server are running the same web documents(html/asp pages etc) designed by the same developer? Don’t think so….

Leave a Reply

Yes, I would like to receive notification on incoming comments!


WordPress Lightbox 2 by Zeo