BetaONE will rise again!


Reply
  #1  
Old 29th Apr 08, 12:51 PM
NewsBot's Avatar
NewsBot NewsBot is offline
Senior Member
 
Join Date: Oct 2004
Posts: 30,379
NewsBot will become famous soon enough
Experts: Don't blame Microsoft for mass site defacements
Progress was made Monday in mitigating thousands of SQL-based Web sites injected with malicious javascript code. However, one security expert says we can expect more such attacks in the near future. A traditional SQL injection attack allows malicious attackers to execute commands on an application's database by injecting executable code. "What's different about this latest attack is the size and the level of sophistication," said Jeremiah Grossman, CTO of White Hat Security.

On Friday, Microsoft denied that new vulnerabilities within Internet Information Services are to blame for a rash of Web site defacements. Microsoft insists it's the application developer's responsibility to follow the company's best practices. These include constraining and sanitizing input data, using type-safe SQL parameters for data access, and restricting account permissions in the database.

Grossman agreed it's not Microsoft's fault, and said the attacks could have easily targeted another vendor's software. If users surf to an SQL-injected site, their browser will attempt to download a variety of exploits, not all of which are Microsoft-based. One site from the Shadowserver Foundation lists exploits affecting Real and other vendors alongside various Microsoft Security bulletins.

View: Full Article @ CNet News.com

Read full story...



More...
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Microsoft Opens Personal Health Record Site NewsBot ieXbeta News 0 10th Oct 07 04:55 AM
Microsoft revises anti-Linux campaign with new site NewsBot DriverHeaven News 0 27th Aug 07 02:46 PM
Microsoft confirms Office 12 will be Office 2007 NewsBot NeoWin News 0 16th Feb 06 12:30 PM
Microsoft plans to give some pirates a break Alpine BetaONE News 0 5th May 05 03:51 AM
Neowin Talks Security with Microsoft NewsBot NeoWin News 0 7th Feb 05 01:00 AM


All times are GMT +1. The time now is 09:38 AM.


Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.