One in Nine IIS Servers Compromised, Survey Says
Organizations are lax at patching holes that allow Code Red and Nimda worms to slither in.
Sam Costello, IDG News Service
One in nine servers running Microsoft's Internet Information Server has software installed on it that would allow attackers to take complete control of the system, according to a new survey by Web server information firm Netcraft.
The survey, conducted in October, found that 11 percent of all queried servers running IIS have the "root.exe" hacking program installed on them. That figure is up from the 8.5 percent found in September. Netcraft sends a monthly automated query to servers to discover information such as what software runs the server, what average server uptime is and what security flaws are present in servers. The October survey drew data from 33.1 million Web sites.
IIS security has come under particular scrutiny in recent months as at least half a dozen serious security flaws in IIS have been discovered since January, and two major Internet worms, Code Red and Nimda, have exploited those flaws to infect hundreds of thousands of IIS systems worldwide. Microsoft's own Hotmail servers became infected with the Code Red worm. IIS is bundled with Windows 2000, and is set by default to be enabled.
Although patches have been issued for all those security holes, not all vulnerable systems have had the patches applied, so both worms were able to cause substantial inconvenience and even forced some companies offline. A new Nimda worm appeared last week, exploiting the same flaws as the first Nimda, which evidently had not been patched on many servers.
Holes Proliferate
The presence of four other IIS security flaws rose from September to October, the survey found. The "Administration pages accessible" hole was present on 25 percent of machines, up from 17 percent in September; the "Sample pages and scripts" problem jumped from 17 percent to 26 percent of systems; the "Server paths revealed" flaw was found on 10 percent of systems, up from 8.5 percent; and 2.5 percent of systems were vulnerable to the Code Red worm, up from zero the month before.
The survey also found that a number of Web sites had moved from using IIS to competitor's products. Over the course of the month, more than 1500 sites moved from IIS to Zeus Technology's Web server, and more than 1700 moved to Netscape Communications' server. Open-source server Apache also gained substantial market share, Netcraft said. Netcraft also noted that a number of vendors offered promotions and discounts to entice IIS users to their products.
Patches for the security holes in IIS can be obtained at Microsoft's site.
Mobile Computing
The Best of PC World
Dell's December Days of Deals
-
Dell's December Days of Deals
8 days of deals December 4th to 11th.
Check each day for big savings on Laptops, Desktops, HDTVs, Games and more!
Featured APC Accessories
-
APC Back-UPS ES
Safeguards your equipment from damaging surges and spikes that travel along your utility & data lines.
- APC Smart-UPS Loaded with cutting-edge features, unique battery life predictor, unbeatable on-line efficiencies and software agents allowing remote UPS monitoring. Get 10% off your entire kart purchase!
People who read this also read:
Best Prices on Security Software
Norton Internet Security 2010 - 3 UsersPrice: $26.40
Norton 360 Version 3.0 - 3 UsersPrice: $39.99
AntiVirus Plus 2010 - 3 Users (Full Product)Price: $11.95
Norton Internet Security 2010 - 3 UserPrice: $26.40
Norton 360 Version 3Price: $38.98
Internet Security 2010Price: $32.99
- 15 Minutes to a Secure Business Get the Secure in 15 toolkit starting with the "15 Minutes Month-at-a-Glance" calendar. McAfee will send you additional tools and tricks to stay protected around the clock.
- A Buyer's Guide to Data Protection Implementing data protection products and processes can be daunting. Make the right decisions by exploring what is available and what makes sense for your organization. Use this simple guide to evaluate different vendor offerings.
Cameras
Camcorders
Cell Phones
Components
Desktops
HDTV
Home Theater
GPS
Laptops
Monitors
MP3 Players
Networking &
Printers
Storage


