internet.com
You are in the: Small Business Computing Channelarrow
Small Business Technology
» ECommerce-Guide | Small Business Computing | Webopedia | WinPlanet |Refer-It

WinPlanet Software Downloads and Reviews for Small Businesses
Search
Power Search | Tips
-
Navigate WinPlanet
WinPlanet Home Page

Software
Download Index
In-Depth Reviews
Tips & Tutorials
Updates
News

Software Categories
Browsers
Chat / Conferencing
Desktop Utilities
Development
Internet Apps
Multimedia
OS Service Packs
Productivity Tools

Software Glossary

WinPlanet Newsletter

internet.commerce
Partners & Affiliates













Small Business Computing
Small Business Computing
Ecommerce Guide
Webopedia
WinPlanet

WinPlanet / News

Download of the day
Internet Explorer 8

Most Popular Software Downloads
Mozilla Firefox 3.0
Adobe Reader
Ad-Aware 2008 Free
QuickTime for Windows
Internet Explorer 7
Paint Shop Pro
Windows Live Suite
AVG Anti-Virus Free
Opera
CCleaner (Crap Cleaner)

Most Popular Software Articles
Windows Vista Tips & Tricks, Part 1
Windows Vista: Worthy of the Hype?
Windows Wireless Zero Configuration: Five Steps to Sanity


Software Reviews

Microsoft IIS a Popular Target For Malware
IIS as Popular as Apache Server for Malware
Andy Patrizio

Google's security team has published a report that indicates Microsoft Internet Information Server (IIS) is as popular a target for delivering malicious payloads as its main, and more widely-used, rival, Apache Server.

The report from Nagendra Modadugu of Google's (Quote) Anti-Malware Team found that while Apache has almost three times the installed base – 66 percent to 23 percent – of IIS, the percentage of servers with malware (define) was evenly split, 49 percent each.

Google's security team checked servers running roughly 80 million domain names, noting that it is not unusual to find hundreds of domains served by a single IP address and hence, a single machine.

They found a total of 70,000 domains that over the past month have been either distributing malware or have been responsible for hosting browser exploits leading to drive-by-downloads.

The breakdown is odd. In Germany, almost all of the malware was hosted on Apache servers, while in the U.S., around 75 percent of the malware was on Apache. But in South Korea, 75 percent of the malware was on IIS and nearly all of the malware in China was on IIS servers.

Google's security team wrote that it suspects that the causes for IIS featuring so prominently, particularly in Asia, is because Microsoft (Quote) has engineered its software so pirated copies cannot be fully patched. Piracy in Asia has been a problem for years and is a major thorn in Microsoft's side.

"In summary, our analysis demonstrates how important it is to keep Web servers patched to the latest patch level," wrote the Google group.

One option would be for Microsoft to make patches available for all versions of IIS, legitimate or not. Or, Alex Shipp, an "imaginer" with security vendor MessageLabs, has another solution: "These people could buy licenses," he told internetnews.com.

It certainly wouldn't make sense for Microsoft to make patches work on pirated software, he argues. "If someone steals stuff from you, it seems a bit ridiculous to allow them to keep stealing from you," he noted.

Microsoft did not with to want to discuss the blog at length, but it did issue the following statement to internetnews.com:

"Based on the data provided, it is difficult to draw any viable conclusions about the security of the Web servers mentioned or what the intended use of a given Web server was in this particular investigation. As the blog points out, the administrator's intended use could be to intentionally distribute malware. In addition, the margin of error is extremely large due to that fact that a single Web server can host thousands of sites."

Shipp noted that Apache is totally free. The only thing the Apache Foundation sells is support licenses. This means there are no problems getting fixes. But that supposes all of the infected servers are infected without the administrator's knowledge.

With e-mail filtering improving, malicious software writers need new ways to get their Trojans and keystroke loggers onto unsuspecting computers, and MessageLabs has been noticing more and more infected Web servers recently.

"Any vector they can [exploit] is now fair play, especially a popular Web site. If you can get into MySpace like they have done several times, you've got loads of victims waiting," said Shipp. "In the past, it was sites you'd expect to be dangerous that were infected. Now it's perfectly legitimate sites that have been compromised."

News courtesy of internetnews.com

June 7, 2007


Download Windows Longhorn Server Now!Download

View All Microsoft Software

Contents:
1. IIS as Popular as Apache Server for Malware






JupiterOnlineMedia

internet.comearthweb.comDevx.commediabistro.comGraphics.com

Search:

Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

Jupitermedia Corporate Info


Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers

Solutions
Whitepapers and eBooks
IBM eBook: Planning a Service Oriented Architecture
IBM eBook: Choosing the Right Architecture--What It Means for You and Your Business
Microsoft Article: Will Hyper-V Make VMware This Decade's Netscape?
Avaya Article: Using Intelligent Presence to Create Smarter Business Applications
Intel Go Parallel Article: Getting Started with TBB on Windows
Microsoft Article: 7.0, Microsoft's Lucky Version?
Avaya Article: How to Feed Data into the Avaya Event Processor
IBM Article: Developing a Software Policy for Your Organization
Microsoft Article: Managing Virtual Machines with Microsoft System Center
Intel Go Parallel Article: Intel Threading Tools and OpenMP
HP eBook: Storage Networking , Part 1
Microsoft Article: Solving Data Center Complexity with Microsoft System Center Configuration Manager 2007
MORE WHITEPAPERS, EBOOKS, AND ARTICLES
Webcasts
HP Video: StorageWorks EVA4400 and Oracle
HP Webcast: Storage Is Changing Fast - Be Ready or Be Left Behind
Microsoft Silverlight Video: Creating Fading Controls with Expression Design and Expression Blend 2
MORE WEBCASTS, PODCASTS, AND VIDEOS
Downloads and eKits
Red Gate Download: SQL Toolbelt and free High-Performance SQL Code eBook
Iron Speed Designer Application Generator
MORE DOWNLOADS, EKITS, AND FREE TRIALS
Tutorials and Demos
Silverlight 2 App and Walkthrough: Leverage Silverlight 2 with SQL Server and XML
IBM Article: Enterprise Search--Do You Know What's Out There?
HP Demo: StorageWorks EVA4400
Microsoft Article: The Progress and Promise of Deep Zoom
Microsoft How-to Article: Get Going with Silverlight and Windows Live
MORE TUTORIALS, DEMOS AND STEP-BY-STEP GUIDES