Linked by Thom Holwerda on Mon 28th Apr 2008 19:22 UTC, submitted by Hakime
Law and Order Last week, The Washington Post reported that hundreds of thousands of IIS webservers were hacked. Code was placed on them that installed malware on visitors' computers. Among the infectees were websites from the UK government and the United Nations. Initial reports said the attackers used a security vulnerability in Microsoft's IIS, but the company published more information on the attacks today, and denies IIS was compromised.
Permalink for comment 312146
To read all comments associated with this story, please click here.
RE: Three Words
by StephenBeDoper on Wed 30th Apr 2008 15:52 UTC in reply to "Three Words"
StephenBeDoper
Member since:
2005-07-06

Or - at the *very* least - create a DB user with read-only permissions for the publicly-accessible portions of a web-based app (no write privs. == injection no worky).

Reply Parent Bookmark Score: 2