MacDailyNews - Where Mac news comes first

 MacDailyNews Poll

5 Day Most Commented

Opinion Archive

Current Headlines

Latest Joy of Tech

  • Latest Joy of Tech!

MacNN

AppleInsider

Macworld UK

TUAW

MacRumors

Yahoo! Finance AAPL

iTunes Top 10 Albums

Mac OS X Downloads

Fri, Nov 21, 2008 - 09:37 AM EST  —  AAPL: 80.49 (0.00, +0%)  |  NASDAQ: 1316.12 (0.00, +0%)

Hundreds of thousands of Microsoft web servers hacked; including government servers
Sunday, April 27, 2008 - 01:49 PM EST

"Hundreds of thousands of Web sites - including several at the United Nations and in the U.K. government -- have been hacked recently and seeded with code that tries to exploit security flaws in Microsoft Windows to install malicious software on visitors' machines," Brian Krebs reports for The Washington Post.

"The attackers appear to be breaking into the sites with the help of a security vulnerability in Microsoft's Internet Information Services (IIS) Web servers," Krebs reports.



"On Thursday, Spanish anti-virus vendor Panda Security said that it had alerted Microsoft that a flaw IIS was the cause of all the break-ins. When I asked Microsoft whether they'd heard from Panda or if the hundreds of thousands of sites were hacked from a patched or unpatched flaw in IIS, a spokesman for the company didn't offer much more information," Krebs reports.

"'Microsoft is currently aware of and is receiving reports regarding public claims of attacks on IIS Web servers,' said Bill Sisk, a security response manager at Microsoft, in a statement e-mailed to Security Fix. 'While we have not be [sic] contacted directly regarding these reports, we will continue to monitor all reports either publically [sic] shared or responsibly disclosed and investigate once sufficient details are provided. We have not yet determined whether or not these reports are related to Microsoft Security Advisory (951306) released last week,'" Krebs reports.

"According to Finnish anti-virus maker F-Secure, the number of hacked Web pages serving up malicious software from this attack may be closer to half a million," Krebs reports.

Full article here.

[Thanks to MacDailyNews Reader "RadDoc" for the heads up.]

MacDailyNews Take: UNIX 03 compliance, cross-platform capabilities, and no client-access licenses make Mac OS X Server v10.5 Leopard a rock-solid network foundation. Mac OS X Server v10.5 Leopard brings its enhanced multicore performance, astounding system improvements, and powerful new features to Xserve. Now you can easily set up and manage servers, add new clients to the network, share calendars, schedule meetings, and more. Leopard Server is built on a fully compliant UNIX foundation. This rock-solid core provides the stability, performance, and security that organizations require — and full UNIX conformance ensures compatibility with existing server and application software. An Open Brand UNIX 03 Registered Product, Mac OS X Server can compile and run all your existing UNIX code. So you can deploy it in environments that demand full conformance, complete with hooks to maintain compatibility with existing software. With out-of-the-box support for Mac, Windows, UNIX, and Linux clients, Xserve is the easiest way to provide powerful, innovative network and Internet services for multiplatform workgroups. And there are no client-access licenses, which means no extra fees. Leopard Server supports 64-bit addressing and large LUNs without requiring you to buy a special enterprise version. Buy Xserve with Mac OS X Server v10.5 Leopard Unlimited-Client Edition for just $2,999.

  • Social Web
  • E-mail






Always -- Free ground shipping with orders over $50 at the Apple Store.

Reader Feedback: ( = registered)

Apr 27, 08 - 12:54 pm Comment from: Me In LA

XSERVE ad right in the middle - CLASSIC!

Apr 27, 08 - 12:55 pm Comment from: gow

Not that Microsoft ever has a good week, but this one has been bad even by their standards.

Apr 27, 08 - 12:55 pm Comment from: John

Heh, Bill Sisk can't even write a proper sentence, which doesn't give me great confidence in his management abilities!

Apr 27, 08 - 01:02 pm Comment from: David Baker

A Mac mini, Leopard Server, and hosting in a good data center.

The perfect server for 95% of the people. Inexpensive and powerful.

Apr 27, 08 - 01:04 pm Comment from: almux

I can only repeat myself:
Doomed! M$ is doomed, once for all! wink

Apr 27, 08 - 01:35 pm Comment from: Dave

FYI

Apr 27, 08 - 01:44 pm Comment from: fatal

viewmymessage.com is down, wonder if it is IIS

I fscking hate viewmymessage it is the single biggest flaw of iphone

Apr 27, 08 - 01:52 pm Comment from: Tommy

My support for Apple products has never been questioned or attacked, so I'll say that it makes no sense to revel in the misfortune of MS. So how is it that disparaging MS, Bill Gates, or Baldy Balmer make Apple any better for the effort?

That's my 2 pennies worth.

Apr 27, 08 - 01:59 pm Comment from: Name

A unix based server running an OS like linux/bsd/OS X is the best there is.

Apr 27, 08 - 02:01 pm Comment from: Gabriel

[…] 'While we have not be [sic] contacted directly regarding these reports, we will continue to monitor all reports either publically [sic] shared or responsibly disclosed […]'

For a brief horrifying moment I afraid that second “sic” typo was because the text read “we will continue to monitor all reports either pubically shared” – clearly, the story about the returned Dell laptop still lingers in the dark recesses of my mind…

Apr 27, 08 - 02:04 pm Comment from: IKON

Nothing is 100% save.

oh, it's microsoft hahahahaha wink

Apr 27, 08 - 02:16 pm Comment from: Wandering joe

All your servers are belong to us!! (sick)

Apr 27, 08 - 02:44 pm Comment from: Hm...

Is this why, back at the beginning of '06, M$ had to buy market share for IIS?

C.f.: Netcraft Web server market share data

Apr 27, 08 - 02:45 pm Comment from: Crabapple

Wot?! No blood on the X-server floor headline???

Apr 27, 08 - 02:59 pm Comment from: Bungieinberkeley

Hundreds of thousands of Microsoft web servers hacked; including government servers; Mac Xserves unaffected.

Apr 27, 08 - 03:09 pm Comment from: HMCIV

Ah but I heard a rumor from a friend of a MySpace friend that he saw on a security blog that Apple might be vulnerable to... something.

So I guess that means we should stick to Window$.

Apr 27, 08 - 03:25 pm Comment from: Petey

If your company relies on M$ servers then you might as well close the business down.

It's like playing Russian Roulette - but with your data instead of a gun.

Apr 27, 08 - 03:55 pm Comment from: AppleMacMan

You know, these IT people need re-educating. Why would you use a M$ server in the first place? It's always wide open to attacks. Not only is Mac OS X Leopard Server far more secure, it's also easier to deploy and has far more features.

Apr 27, 08 - 04:32 pm Comment from: MikeR

The headline in Computerworld:

"Microsoft: Massive site attacks not our fault
No bugs in IIS or SQL Server, says company"

http://www.computerworld.com/action/article.do?command=viewArticleBasic&taxonomyName=development&articleId=9080678&taxonomyId=11&intsrc=kc_top

Denial is the first sign.

Apr 27, 08 - 04:48 pm Comment from: OZZ

@Petey:

Couldn't say that any better!!!!

Apr 27, 08 - 04:49 pm Comment from: opie

There goes all that passion and potential out the window once a gain. One of the definitions for insanity is the expectation that you can do the same things over and over again yet expect different results.

Apr 27, 08 - 05:13 pm Comment from: Scott

the worst part of the viewmymessage.com is that it hardly works right on the actual iphone or from a computer. Maybe iPhone software 2.0 will help it.

Apr 27, 08 - 07:32 pm Comment from: Hint Hammer

Tommy,

Listen friend, don't let the irony of you chastising us for calling people names go unnoticed.


MW: think. No shite!

Apr 27, 08 - 07:38 pm Comment from: doc

Hundreds of thousands!! Hundreds of thousands!! Hundreds of thousands!! Hundreds of thousands!! Hundreds of thousands!! Hundreds of thousands!! Hundreds of thousands!! Hundreds of thousands!! Hundreds of thousands!! Hundreds of thousands!!

Apr 27, 08 - 08:00 pm Comment from: G4Dualie

If your company relies on M$ servers then you might as well close the business down.

Don't be absurd. The threat isn't Microsoft, it's the insurance industry.

However, if your company relies on government cheese, then you might as well close the business down cause you'll be caught standing when the music stops; a great culling of the market place is forthcoming.

Keep your eye on the insurance industry though. There is a shitty little business arm of the industry, who are like scavengers that come in after the carnage to initiate damage control and preserve what's left.

Some of these companies hire unscrupulous IT who can sift through a company's data like tea leaves from which emerges a highly-accurate picture of not only the health of your company, but your employees too. Insurance companies see it as a proactive measure to protect their investment.

Think about it. The insurance industry is in bed with the medical industry and together they have access to just about every intimate aspect of this nations deepest, darkest secrets.

If an insurance company wanted to cull a company from the pack they need only find an area on the grid that is the weakest link. In this case it's the IIS web servers.

Microsoft gets blamed in the press and the insurance industry recedes quietly back into the background.

Cue the organ music... curtain... house lights...

LOL

Apr 27, 08 - 08:14 pm Comment from: HotinPlaya

Did you read the comments to the story?

Those people are in denial

Apr 27, 08 - 09:25 pm Comment from: ichi

nice work dualie.

(someone on here was supposed to send me directions to the pre-rev meet up., oh well, i'm sure i'll be present and accounted for, with left-hand raised high, when the time comes.)

Apr 27, 08 - 09:50 pm Comment from: shen

nah, this can't be true, cause i read the windows news headline "Windows 2003 Hacked Less Often Than Linux"

heck they say in 7 years windows was hacked .8 million times. this article says .5 million in two weeks......

that is some curve!

Apr 27, 08 - 11:30 pm Comment from: His Shadow

Here's a clue that just fucking hit me the other day and I am baffled why I never thought of the current situation this way.

Why, exactly, does any Microsoft Windows house pay a per user fee? Why? You've already paid that fee by having to have a legit copy of windows on every single box already in your organisation! How did corporate Amercica fall for this outright scam in such a huge way? What kind of idiots are running corporate America that this near criminal situation was allowed to flourish?

But then one only has to look at the current mortgage crisis meltdown to realise that too many people in positions of power got there thru luck, not necessarily brains or hard work.

Apr 28, 08 - 12:11 am Comment from: Pete

Let us not forget that the Swiss report and the hacking contest last month have already proven that Windows is more secure than Mac OS X.

... Not!

Apr 28, 08 - 01:27 am Comment from: Andrus

OS X Server is not without its share of flaws. Some of them are VERY serious. For example the VPN service in 10.4.11 will eventually bring down the whole server. 10.5.2 has even more problems, just have a look at the support forums. No need to hype OS X Server, maybe at 10.5.10 it will be stable and bugfree enough to be taken seriously. No bashing intended, I am just disappointed with OS X Server. The desktop OS X on the other hand is much better.

Apr 28, 08 - 03:34 am Comment from: Olmecmystic

Where's Poon Tang when you need him?

Buehler? Poon Tang? Buehler?

Cue the "crickets" sound effect...

Peace.
Olmecmystic wink

Apr 28, 08 - 04:22 am Comment from: British Mac Head

Where's MDN's own officially elected Microsoft spokesperson?
Zune Tang, your defence please grin

fnar fnar!

Apr 28, 08 - 06:54 am Comment from: LOL

Comment from: G4Dualie 
If your company relies on M$ servers then you might as well close the business down.

Don't be absurd. The threat isn't Microsoft, it's the insurance industry.
------------------------------------
I can’t disagree more ...

Apr 28, 08 - 09:09 am Comment from: Predrag

While Mac Mini might be a more secure server than an IIS (regardless of hardware), it is foolish to recommend a Mac Mini as a server. I'm sure DavidBaker meant that as a slight exaggeration; for those who took it seriously, please, don't do that. If you're building a server, spend an extra two grand and get a Mac Pro. Mac Mini has a laptop hard drive. It is in fact a screenless laptop. It would be extremely shortsighted to expect Mini to be able to endure the pounding an average server gets. Get a refurbished Mac Pro (or X-serve) and you have the best, cheapest, most reliable server machine there is.

Apr 28, 08 - 09:55 am Comment from: ApplePi

If you really want to hack a server, I mean really wanna get into it, for corporate sabotage... you only need to keep trying.

OSX servers just haven't been around long enough and been in the right places for someone to pay enough to commit corporate sabotage. Put 1/2 million of them out there in large corporations and let's see how they do.

The only reason why suits use Microsoft and shitty PCs is they don't know any better. IT people have jobs because of the Microsoft PC. A whole micro-industry is based on keeping up with a dinosaur OS that people are afraid of leaving. How many companies are out there that just offer spyware and virus software. Supporting the Microsoft way of life is a multi billion dollar business. It will die hard people.

This is why people will spend whatever Microsoft says they will spend, and do what Microsoft says to do. After all, they are in the business of business, not computers or software.

- Pi has spoken

Apr 28, 08 - 10:36 am Comment from: Mad Mac Maniac

THIS IS WHY YOU SHOULDN'T PUT ANY M$ SOFTWARE ON YOUR MAC!!

95% of exploits are in APPLICATIONS!!

Do the research yourself...

Let M$ die, get NeoOfficeJ, it's free!!!

Apr 28, 08 - 11:45 am Comment from: Ampar

"Nowadays, security guys break the Mac every single day. Every single day, they come out with a total exploit, your machine can be taken over totally. I dare anybody to do that once a month on the Windows machine."
- Bill Gates

Apr 28, 08 - 01:25 pm Comment from: @MacDailyNews Take

Zune Tang - Is that you?

Apr 28, 08 - 02:57 pm Comment from: eth0

POW! Right in the kisser!

Apr 28, 08 - 07:18 pm Comment from: Macintosh

Coolness.

Reader feedback page 1 of 1 pages:

Always -- Free ground shipping with orders over $50 at the Apple Store.

Add Your Feedback:

Register or Login

Name:

Email: (optional)

Emoticons | Allowed HTML Tags

Remember my personal information   Notify me of follow-up comments?

Please enter the "MDN Magic Word" you see in the image below: