<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Visual Studio, VSIP Partners and more ...... : IIS Security VS</title><link>http://blogs.msdn.com/terryclancy/archive/tags/IIS+Security+VS/default.aspx</link><description>Tags: IIS Security VS</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Protect your IIS Server from attack.</title><link>http://blogs.msdn.com/terryclancy/archive/2008/04/26/protect-your-iis-server-from-attack.aspx</link><pubDate>Sat, 26 Apr 2008 04:18:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8425252</guid><dc:creator>terrycl</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/terryclancy/comments/8425252.aspx</comments><wfw:commentRss>http://blogs.msdn.com/terryclancy/commentrss.aspx?PostID=8425252</wfw:commentRss><description>&lt;P&gt;Recent articles such as the&amp;nbsp;internetnews.com&amp;nbsp;article&amp;nbsp;&lt;A class="" title="internetnews.com artical on IIS attack" href="http://www.internetnews.com/security/article.php/3742926/HalfMillion+IIS+Servers+Hit+in+Cyber+Attack.htm" mce_href="http://www.internetnews.com/security/article.php/3742926/HalfMillion+IIS+Servers+Hit+in+Cyber+Attack.htm"&gt;here&lt;/A&gt;&amp;nbsp; and Sans article &lt;A class="" title="Sans Article" href="http://isc.sans.org/diary.html?storyid=4294&amp;amp;rss" mce_href="http://isc.sans.org/diary.html?storyid=4294&amp;amp;rss"&gt;here&lt;/A&gt; report that there is currently a cyberattack underway targeting vulnerable Internet Information Server-based Web pages by redirecting visitors to the site toward one hosting malicious code, and it's growing rapidly. &lt;/P&gt;
&lt;P&gt;The malicious code&amp;nbsp; uses search engines in order to find potentially vulnerable applications and then tries to exploit them. The exploit just consisted of an SQL statement that tried to inject a script tag into every HTML page on the web site. More specifically they appear to be SQL injecting IFRAMEs into the vulnerable servers, those IFRAMEs contain the malicious code.&lt;/P&gt;
&lt;P&gt;The problem is apparently centered around IIS Web server because the hackers are targeting Microsoft's ASP pages which use SQL Server. &lt;/P&gt;
&lt;P&gt;To protect your web servers from these attacks ensure that your web server code is not vulnerable to SQL injection attacks&amp;nbsp;by&amp;nbsp;reviewing your code or by using VS integrated security tools from VSIP Security Partners as listed &lt;A class="" title="VSIP Partner Security Tools" href="http://msdn2.microsoft.com/en-us/vstudio/products/cc197930.aspx" mce_href="http://msdn2.microsoft.com/en-us/vstudio/products/cc197930.aspx"&gt;here&lt;/A&gt;&amp;nbsp;. &lt;/P&gt;
&lt;P&gt;The tools most likely to be of use to you are Fortify SCA, HP DevInspect, and Ounce Security Analyst.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;&amp;nbsp;If you use VSTS Team Foundation Server (TFS)&amp;nbsp;consider tools that integrate with TFS so that source code scanning can be enforced by policy as part of code checkin, build or on a scheduled basis.&lt;/P&gt;
&lt;P&gt;Also the Sans article &lt;A class="" title="Sans Article" href="http://isc.sans.org/diary.html?storyid=4294&amp;amp;rss" mce_href="http://isc.sans.org/diary.html?storyid=4294&amp;amp;rss"&gt;here&lt;/A&gt; contains a list of on-line resources to help you how to check your applications and make sure that they are not vulnerable.&lt;/P&gt;
&lt;P&gt;Also it is always good practice to ensure that your web servers are up-to-date with all patches although this will not protect you from SQL injection attacks&amp;nbsp;resulting from poorly written code.&lt;/P&gt;
&lt;P mce_keep="true"&gt;Hope this helps&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Terry&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8425252" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/terryclancy/archive/tags/IIS+Security+VS/default.aspx">IIS Security VS</category></item></channel></rss>