Microsoft patches ten IIS vulnerabilities
News Microsoft has long recommended disabling .htr, and the .htr file request buffer overflow threat is disabled by all releases of the IIS Lockdown Tool. In what can only be viewed as a bad week for Microsoft, the company recently disclosed that a full...
[April 29, 2002, 13:39]
Microsoft warns of attacks using IIS flaw
News Microsoft disclosed the Internet Information Services (IIS) vulnerability on Monday, and on Friday said it is still working on a security update to fix the problem. According to the advisory, the vulnerability could let somebody run arbitrary code...
[September 7, 2009, 8:12]
IIS flaw under investigation by Microsoft
News In a statement, a Microsoft representative said the company "is investigating new public claims of a possible vulnerability in IIS 5 and IIS 6 File Transfer Protocol (FTP)". IDG said the exploit appears to affect primarily older versions of IIS...
[September 1, 2009, 15:15]
Microsoft to fix zero-day SMB, IIS holes
News Microsoft, which previously released a temporary fix for the SMB hole, reported the Internet Information Services (IIS) flaw in the File Transfer Protocol in August. For the full story, see Microsoft to patch zero-day SMB, IIS holes at CNET News.
[October 9, 2009, 14:19]
FBI: Microsoft IIS most vulnerable
News This year it's Microsoft IIS," Paller says, "because it's so widespread and so easy to break into. But if they don't explicitly disable it, the hidden version of IIS can simply run in the background, providing a back door into the computer on which...
[November 8, 2001, 9:40]
Gartner advises companies to scrap Microsoft IIS
News Research group Gartner is warning enterprises to "immediately" replace their Microsoft Internet Information Server (IIS) server software with a more secure server application, following attacks on IIS by the worms Code Red and Nimda.
[September 25, 2001, 12:30]
One Year Ago: Microsoft posts fix for IIS security hole
News Microsoft has posted a description and fix to prevent hackers causing Internet Information Server (IIS) to crash when they enter certain URLs. It forces IIS to become unavailable for a short time and is easily remedied by restarting the Web server.
[June 23, 1998, 6:13]
Microsoft issues advisory on IIS security problem
News Microsoft on Tuesday issued a security advisory for a Web server flaw that was made public on Monday. The flaw affects certain versions of Microsoft Internet Information Services product, but to be exploited it requires a user to have the FTP...
[September 2, 2009, 10:09]
Securing Your Microsoft Internet Information Services (MS IIS) Web Server with a thawte Digital Certificate
White Papers This guide will explain the various ways in which your business can benefit if you secure your MS IIS server with a Thawte digital certificate. Learn how you can build customer confidence around Internet security.
[March 5, 2009, 9:30]
Microsoft Internet Information Services: Isolating and Securing Web Applications in IIS 6.0
White Papers Microsoft Internet Information Services (IIS) administrators frequently configure multiple Web sites on a single server. This WebCast will review the security features of IIS 6.0 in Windows Server 2003 and discuss how to use them to secure Web...
[November 5, 2003, 23:00]
US Report: Microsoft warns of IIS security hole
News Remote Data Service is installed by default when IIS 4.0 is implemented using the Microsoft Windows NT Option Pack. Microsoft's IIS development team discovered that a component of Remote Data Service, DataFactory, allows an intruder who has gained...
[July 20, 1998, 6:40]
TeleWest to move to Zeus
News TeleWest is to move its shared Web hosting service from Microsoft's IIS to Web servers from UK-based Zeus Technology. It is also capitalising on fears of the insecurity of Microsoft's IIS server to sell Zeus as a load balancing firewall for IIS...
[November 14, 2001, 14:29]
Zeus 4.0 cashes in on Microsoft security fears
News UK-based Zeus Technology is hoping to cash in on security fears over Microsoft's IIS Web server software with the first major upgrade to its own namesake Web server in four years. Earlier in October, analyst firm Gartner Group issued a statement...
[October 17, 2001, 12:20]
Worm exploits Solaris to attack IIS sites
News New computer worm exploits a known vulnerability in Solaris to attack Websites based on Microsoft's IIS server Dubbed the sadmind/IIS -- after the exploits used -- the worm targets computers running Sun's Unix-based operating system Solaris to...
[May 8, 2001, 13:35]
Security expert warns of 'token kidnapping' threat
News Hosting providers and IT professionals have been warned of a threat posed to Microsoft IIS web servers through exploitation of vulnerabilities in Microsoft operating systems. The technique works by elevating privileges through exploiting accounts...
[May 21, 2008, 15:33]
Queen banishes Linux
News The Queen, or at least her new Web hosting company, has dumped GNU/Linux in favour of Microsoft IIS Web servers, ending the royal family's two-year flirtation with the open-source operating system. She also said that Linux is easier to administer...
[December 5, 2001, 13:50]
Microsoft fixes critical server bugs
News Microsoft has released a patch for ten new vulnerabilities in newer versions of its Internet Information Services (IIS) server software, some of which are serious enough to allow attackers to take over the server and execute any code of their...
[April 10, 2002, 16:31]
What's New in IIS 7
White Papers Microsoft Internet Information Server (IIS) has been observing a steady growth since they released IIS 6.0. Its never enough though, as IIS folks at Microsoft continued their effort to make it better in than before with security at its paramount...
[October 18, 2006, 0:00]
Microsoft patches new security flaws
News The higher-rated of the two bulletins includes a patch that fixes four separate vulnerabilities in Microsoft's Internet Information Services (IIS) software. We definitely want everyone who is running IIS 4.0, 5.0 and 5.1 to install the patch," said...
[May 29, 2003, 7:47]
Microsoft races to fix security hole
News Web servers using Microsoft's IIS 4.0 software are not affected by the flaw. Companies that have set up their Web server with the printing turned off -- as outlined in Microsoft's "IIS Security Checklist" guidelines -- or used the IIS Security...
[May 2, 2001, 8:32]



