<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Questions about Web Server Attacks</title><link>http://blogs.technet.com/msrc/archive/2008/04/25/questions-about-web-server-attacks.aspx</link><description>Hi there this is Bill Sisk. There have been conflicting public reports describing a recent rash of web server attacks. I want to bring some clarification about the reports and point you to the IIS blog for additional information. To begin with, our investigation</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>IIS at risk?</title><link>http://blogs.technet.com/msrc/archive/2008/04/25/questions-about-web-server-attacks.aspx#3045203</link><pubDate>Sat, 26 Apr 2008 09:10:13 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3045203</guid><dc:creator>The Official Blog of the SBS "Diva"</dc:creator><description>&lt;p&gt;I got a ping today asking if SBS 2003 was vulnerable to this Security Advisory... Microsoft Security&lt;/p&gt;
</description></item><item><title>IIS at risk?</title><link>http://blogs.technet.com/msrc/archive/2008/04/25/questions-about-web-server-attacks.aspx#3045213</link><pubDate>Sat, 26 Apr 2008 09:36:36 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3045213</guid><dc:creator>MVPs</dc:creator><description>&lt;p&gt;I got a ping today asking if SBS 2003 was vulnerable to this Security Advisory... Microsoft Security&lt;/p&gt;
</description></item><item><title>Recent slate of IIS attacks - more info</title><link>http://blogs.technet.com/msrc/archive/2008/04/25/questions-about-web-server-attacks.aspx#3045355</link><pubDate>Sat, 26 Apr 2008 15:24:43 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3045355</guid><dc:creator>K. Brian Kelley - Databases, Infrastructure, and Security</dc:creator><description>&lt;p&gt;The recent slate of attacks on IIS servers don&amp;amp;#39;t seem to be an attack directly against IIS or against&lt;/p&gt;
</description></item><item><title>Microsoft denies fault in hacks</title><link>http://blogs.technet.com/msrc/archive/2008/04/25/questions-about-web-server-attacks.aspx#3045991</link><pubDate>Mon, 28 Apr 2008 00:36:40 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3045991</guid><dc:creator>pcpartfinder</dc:creator><description>&lt;p&gt;Microsoft is denying that a recent rash of Web server attacks are the company&amp;amp;#39;s fault. In a blog&lt;/p&gt;
</description></item><item><title>Microsoft IIS Web servers hit by widespread SQL injection attacks</title><link>http://blogs.technet.com/msrc/archive/2008/04/25/questions-about-web-server-attacks.aspx#3046084</link><pubDate>Mon, 28 Apr 2008 04:59:02 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3046084</guid><dc:creator>Microsoft News Tracker</dc:creator><description>&lt;p&gt;Over the last week there have been a number of reports of automated SQL injection attacks on Web sites running Microsoft&amp;amp;#8217;s flagship IIS Web server. The Washington Post&amp;amp;#8217;s Brian Krebs summarizes them nicely in Hundreds of Thousands of Micros..&lt;/p&gt;
</description></item><item><title>Nuova ondata di attacchi SQL Injection/iFrame: l'importanza della sicurezza applicativa e del security patching</title><link>http://blogs.technet.com/msrc/archive/2008/04/25/questions-about-web-server-attacks.aspx#3046340</link><pubDate>Mon, 28 Apr 2008 17:06:27 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3046340</guid><dc:creator>Security Blog di Feliciano Intini</dc:creator><description>&lt;p&gt;La blogosfera &amp;amp;quot;sicura&amp;amp;quot; (nome scherzoso con cui identifico l'insieme di blog/e-magazines in&lt;/p&gt;
</description></item><item><title>Microsoft Refuses To Take Blame for IIS SQL Injections</title><link>http://blogs.technet.com/msrc/archive/2008/04/25/questions-about-web-server-attacks.aspx#3046394</link><pubDate>Mon, 28 Apr 2008 19:44:50 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3046394</guid><dc:creator>BestBizWare</dc:creator><description>&lt;p&gt;If your business&amp;amp;rsquo;s Website has been hacked in recent weeks via SQL injection attacks, don&amp;amp;rsquo;t blame Microsoft. Heck no. Not even if it&amp;amp;rsquo;s their fault. A Microsoft manager said the following in response to questions: &amp;amp;quot;Our investigation&lt;/p&gt;
</description></item><item><title>Weak SQL coding techniques result in Huge SQL Injection attacks</title><link>http://blogs.technet.com/msrc/archive/2008/04/25/questions-about-web-server-attacks.aspx#3046415</link><pubDate>Mon, 28 Apr 2008 20:47:29 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3046415</guid><dc:creator>Harry Waldron - My IT Forums Blog </dc:creator><description>&lt;p&gt;A new major security attack occurred over the weekend, where over one half million web pages became infected&lt;/p&gt;
</description></item><item><title>Weak SQL coding techniques result in Huge SQL Injection attacks</title><link>http://blogs.technet.com/msrc/archive/2008/04/25/questions-about-web-server-attacks.aspx#3046416</link><pubDate>Mon, 28 Apr 2008 20:47:58 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3046416</guid><dc:creator>Harry Waldron - Microsoft MVP Blog</dc:creator><description>&lt;p&gt;A new major security attack occurred over the weekend, where over one half million web pages became infected&lt;/p&gt;
</description></item><item><title>Microsoft: Massive site attacks not our fault</title><link>http://blogs.technet.com/msrc/archive/2008/04/25/questions-about-web-server-attacks.aspx#3046426</link><pubDate>Mon, 28 Apr 2008 21:12:10 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3046426</guid><dc:creator>infoworld.com</dc:creator><description>&lt;p&gt;Microsoft late Friday denied that vulnerabilities in its Web and SQL Server software had been exploited&lt;/p&gt;
</description></item><item><title>The recent IIS Attacks</title><link>http://blogs.technet.com/msrc/archive/2008/04/25/questions-about-web-server-attacks.aspx#3047104</link><pubDate>Tue, 29 Apr 2008 23:05:37 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3047104</guid><dc:creator>Roger's Security Blog</dc:creator><description>&lt;p&gt;There has been a lot of discussions in different blogs on the attacks on IIS servers. Microsoft Security&lt;/p&gt;
</description></item><item><title>Hullanak az IIS-ek</title><link>http://blogs.technet.com/msrc/archive/2008/04/25/questions-about-web-server-attacks.aspx#3047527</link><pubDate>Wed, 30 Apr 2008 13:08:07 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3047527</guid><dc:creator>Balássy György (MSDNKK)</dc:creator><description>&lt;p&gt;Az ut&amp;#243;bbi időben egyre t&amp;#246;bb olyan h&amp;#237;r jelent meg a vil&amp;#225;gh&amp;#225;l&amp;#243;n, amelyek szerint durva hiba lehet a Windows&lt;/p&gt;
</description></item><item><title>Web attacks affect 500,000 webpages: Microsoft says not our fault</title><link>http://blogs.technet.com/msrc/archive/2008/04/25/questions-about-web-server-attacks.aspx#3048168</link><pubDate>Thu, 01 May 2008 16:02:28 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3048168</guid><dc:creator>TechReef</dc:creator><description>&lt;p&gt;Microsoft Corp. late Friday&lt;/p&gt;
&lt;p&gt;denied that vulnerabilities in its Web and SQL Server software had been&lt;/p&gt;
&lt;p&gt;exploited to hack hundreds of thousands of Internet pages. Attacks on legitimate Web domains, including some belonging to the &amp;lt;a title=&amp;quot;United Nations&amp;quot;&lt;/p&gt;
</description></item><item><title>Links Roundup</title><link>http://blogs.technet.com/msrc/archive/2008/04/25/questions-about-web-server-attacks.aspx#3048739</link><pubDate>Fri, 02 May 2008 18:47:04 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3048739</guid><dc:creator>enemieslist.com: Spam News</dc:creator><description>&lt;p&gt;Drawing the Line Massive Attack: Half A Million Microsoft-Powered Sites Hit With SQL Injection Questions about Web Server Attacks Microsoft denies fault in hacksThe resulting botnet's mail was the only thing that was making it through my rDNS filters..&lt;/p&gt;
</description></item><item><title>http://blogs.technet.com/controlpanel/blogs/postlist.aspx</title><link>http://blogs.technet.com/msrc/archive/2008/04/25/questions-about-web-server-attacks.aspx#3053099</link><pubDate>Fri, 09 May 2008 22:24:48 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3053099</guid><dc:creator>TrackBack</dc:creator><description /></item><item><title>SQL Injection General Guidance</title><link>http://blogs.technet.com/msrc/archive/2008/04/25/questions-about-web-server-attacks.aspx#3062048</link><pubDate>Wed, 28 May 2008 11:12:49 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3062048</guid><dc:creator>Microsoft Switzerland Security Blog</dc:creator><description>&lt;p&gt;There s a lot of noise arround currently ongoig SQL injection attacks and even if that is quite an &amp;quot;old&amp;quot;&lt;/p&gt;
</description></item><item><title>The latest SQL Injection Attacks</title><link>http://blogs.technet.com/msrc/archive/2008/04/25/questions-about-web-server-attacks.aspx#3063323</link><pubDate>Fri, 30 May 2008 10:41:04 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3063323</guid><dc:creator>Roger's Security Blog</dc:creator><description>&lt;p&gt;Well, there was quite some chatter over the last few weeks with regards to the massive defacements we&lt;/p&gt;
</description></item><item><title>SQL注入攻击-来自微软安全博客的建议</title><link>http://blogs.technet.com/msrc/archive/2008/04/25/questions-about-web-server-attacks.aspx#3066254</link><pubDate>Thu, 05 Jun 2008 06:01:18 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3066254</guid><dc:creator>Applelure</dc:creator><description>&lt;p&gt;本文翻译自微软博客上刊载的相关文章，英文原文版权归原作者所有，特此声明。（特别感谢NeilCarpenter对本文写作提供的帮助）&lt;/p&gt;
&lt;p&gt;近期趋势&lt;/p&gt;
&lt;p&gt;从去年下半年开始，很多网站被损害，他们在用于生成动...&lt;/p&gt;
</description></item></channel></rss>