Home › News › Industry News
Microsoft denies SQL compromises due to IIS
Last week we reported on a massive SQL injection exploit that could be affecting a large number of sites. While the source of the problem was apparent to many, some others were prematurely pointing the finger at IIS, which upset Microsoft.
Seeking to alleviate fears, the software giant has outright denied that IIS is to blame, claiming that the affected servers were not compromised due to security flaws inside IIS or Microsoft SQL Server. At the same time, they pointed to coding practices they feel help prevent such exploits from occurring. Microsoft is certainly correct this time in asserting that IIS is not the source of the problem, though with the troubled history of IIS it is easy to understand why many would assume such.
Seeking to alleviate fears, the software giant has outright denied that IIS is to blame, claiming that the affected servers were not compromised due to security flaws inside IIS or Microsoft SQL Server. At the same time, they pointed to coding practices they feel help prevent such exploits from occurring. Microsoft is certainly correct this time in asserting that IIS is not the source of the problem, though with the troubled history of IIS it is easy to understand why many would assume such.
User Comments (1)
Post a comment|
Nirkon
on April 28, 2008 3:14 PM |
Just because Microsoft said so, doesn't mean its true. |
Most Popular
| Trending | Featured |
-
iOS 5.1.1 untethered jailbreak tool released, supports 4S, iPad 3
-
After five days, Facebook ranks as worst IPO flop of the decade
-
Rumor: Windows 8 RC will launch June 1, will ship with Adobe Flash
-
Rumor: AMD "Piledriver" FX CPU production to begin Q3 2012
-
Diablo III becomes the fastest-selling PC game in history
Editors' Keyboard Picks
Subscribe to TechSpot
Get free exclusive content, learn about new features and tech breaking news.