|
Solaris & IIS At RiskCERT warns of new Internet worm
Worm Infects Microsoft IIS and Solaris Serversby Dave MurphyISSN 1535-3613
The worm takes advantage of known security flaws in both servers' software to compromise systems and deface web pages, according to CERT, which has named the malicious code the "sadmind/IIS worm." "We have received a very large number of reports of systems being compromised by the worm, both Solaris and IIS systems," said Chad Dougherty, Internet security analyst at CERT. "We started receiving reports early on Monday." The Solaris system is entered by using a 2-year-old buffer overflow vulnerability. Then a security hole that was uncovered seven months ago is used to break into the IIS system. Once infected the Solaris system is used to scan and compromise other Solaris systems and IIS systems, CERT said. Patches to both Sun's and Microsoft's software have been publicly available for quite a while. However, it's our experience that many network administrators don't make full efforts to secure their servers, even when patches are freely released and well documented.
Call for CommentsWhat do you think? Leave your comments on the message center.
ReferencesCERT AdvisorySun Microsystems Microsoft Message Center
Related ArticleMicrosoft IIS 5.0 Opens Security Hole in Windows 2000
Damar Group, Ltd. helps business use technology. ITINFO is again accepting sponsors. Sponsor messages are included in ITINFO's email newsletter and are permanently posted to DGL's website and online reference areas. ITINFO is an electronic publication of Damar Group, Ltd., publisher of Training Express computer learning guides. Comments and submissions to info@dgl.com. Previous issues are on our website at http://dgl.com/itinfo/.
updated May 8, 2001
Return to DGL homepage |