UPDATED: Hackers could take control of Microsoft's IIS server
A flaw in IIS could allow the bad guys to come in and take control.

There is a warning of a vulnerability in Microsoft's Internet Information Services (IIS) web server, which could allow hackers to execute code and take control.
The United States Emergency Readiness Team (US-CERT) had posted an advisory about the issue, alerting users to a problem in the Microsoft IIS FTP service.
It was reported that the exploit code was originally posted on the Milw0rm site on Monday, which could soon make real-world attacks a possibility.
IIS 5 and IIS 6 are vulnerable. IIS is the second most popular web server behind Apache, according to statistics from July.
"By issuing an FT NLST (NAME LIST) command on a specially-named directory, an attacker may cause a stack buffer overflow," US-CERT's warning said.
"The attacker can create the specially-named directory if FTP is configured to allow write access using Anonymous account of a another account that is available to the attacker."
Microsoft confirmed the vulnerability in a security advisory, but stressed that it had not seen active attacks using the exploit code.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
-
The UK government wants quantum technology out of the lab and in the hands of enterprises
News The UK government has unveiled plans to invest £121 million in quantum computing projects in an effort to drive real-world applications and adoption rates.
By Emma Woollacott Published
-
Netgear WBE710 review
Reviews The compact WBE710 delivers great cloud management features and a good turn of Wi-Fi 7 speed – but it does have a premium price tag
By Dave Mitchell Published
-
Mitre reveals ten worst hardware security weaknesses in 2021
News The list aims to highlight common hardware flaws to help eliminate them from product development cycles
By Rene Millman Published
-
New malware plants backdoor on Microsoft web server software
News IIS target of hackers looking to enter victim’s infrastructure
By Rene Millman Published
-
HPE warns of a critical zero-day flaw in server management software
News There's a workaround for Windows customers, but nothing for Linux admins
By Danny Bradbury Published
-
BBX BlackBerry Server brings security ruckus for CIOs
News Working with the new BlackBerry Server, BBX will secure enterprise data and provision enterprise apps without blocking consumer apps.
By Mary Branscombe Published
-
DeviceLock 7 review
Reviews Accidental or deliberate data leakage is now a major security headache for businesses. Dave Mitchell takes a look at DeviceLock 7 to see if it plugs those holes that others leave behind.
By Dave Mitchell Published
-
UPDATED: Kaspersky hit by cyber criminals?
News The anti-virus specialists have reportedly been beaten at their own game.
By Jennifer Scott Published
-
DDoS attack turns servers into bots
News A new distributed denial of service attack has been discovered that uses servers to distribute rather than PCs.
By Jennifer Scott Published
-
Microsoft IIS web server under attack from hackers
News The company has said that exploit code targeting the flaw was ‘not responsibly disclosed’.
By Asavin Wattanajantra Published