Mass SQL Injection Attack Hits Sites Running IIS
Trailrunner7 writes "There's a large-scale attack underway that is targeting Web servers running Microsoft's IIS software, injecting the sites with a specific malicious script. The attack has compromised tens of thousands of sites already, experts say, and there's no clear indication of who's behind the campaign right now. The attack, which researchers first noticed earlier this week, already has affected a few high-profile sites, including those belonging to The Wall Street Journal and The Jerusalem Post. Some analyses of the IIS attack suggest that it is directed at a third-party ad management script found on these sites."
in b4 legions of freetards blame this on microsoft and the usual HURR DURR IM RUNNAN LUNIX. even though anyone with half a brain would recognize this as an sql injection, which is 100% platform independant.
Why would ANYONE use IIS for a high traffic, high-profile site? Ridiculous.
... That the volume of Apache and PHP downloads are about to go up.
This is my opinion. To make sure you don't steal it, it's covered by the DMCA.
Companies actually use IIS?!?
There is a war going on for your mind.
why is anybody running IIS anyway... Is this not another outdated technology from mickey$oft.