Comments
Richard Davies wrote: The UK has a good crop of technology pioneers in cloud computing - for example ElasticHosts, FlexiScale, Flexiant, OnApp - and also some strong government initiatives such as G-Cloud. We will have to see whether this kind of technical leadership converts into swift mass-market adoption or not.
Cloud Computing
Conference & Expo
November 2-4, 2009 NYC
Register Today and SAVE !..
SYS-CON.TV
Today's Top SOA Links


IIS Vulnerability Update: Symantec Has (Maybe) Snagged Offending Code
"SSL worm" has maybe already been found

On April 22 Microsoft became aware of code available on the Internet that seeks to exploit vulnerabilities already addressed as part of its April 13 security updates, code that attempts to use the IIS PCT/SSL vulnerability on servers running Internet Information Services with the Secure Socket Layer authentication enabled.  The vulnerability was addressed by bulletin MS04-011 (www.windowsupdate.com) and Microsoft urged all customers to immediately install the MS4-011 update as well as the other critical updates provided on April 13. 

In addition, Microsoft published a knowledge base article KB187498 at http://support.microsoft.com/default.aspx?scid=kb;en-us;187498 which provides additional details on SSL and how to disable PCT without applying MS04-011. 

Now Symantec's "DeepSight Threat" network - a global group of sensors that tracks up-and-coming exploits - is reported to have obtained a copy of the code on April 27.

"The sample is automated code, but whether it's a bot or actually a worm, we don't yet know,"  said Alfred Huger, the senior director of engineering with Symantec's security response team.

Only a worm can infect other systems indirectly, by sending itself via e-mail or tucking copies into shared folders, Huger explained. But either way, he urged everyone to expedite their patching of this vulnerability.

"If this isn't a worm, I think we'll see one in short order," he said.

About Security News Desk
SYS-CON's Security News desk trawls the world of security for news of software, hardware, products, and services that seems likely to be of interest to infosec professionals and summarizes them for easy assimilation by busy IT managers and staff.

In order to post a comment you need to be registered and logged in.

Register | Sign-in

Reader Feedback: Page 1 of 1

Subscribe to the World's Most Powerful Newsletters
Subscribe to Our Rss Feeds & Get Your SYS-CON News Live!
Click to Add our RSS Feeds to the Service of Your Choice:
Google Reader or Homepage Add to My Yahoo! Subscribe with Bloglines Subscribe in NewsGator Online
myFeedster Add to My AOL Subscribe in Rojo Add 'Hugg' to Newsburst from CNET News.com Kinja Digest View Additional SYS-CON Feeds
Publish Your Article! Please send it to editorial(at)sys-con.com!

Advertise on this site! Contact advertising(at)sys-con.com! 201 802-3021

SYS-CON Featured Whitepapers
ADS BY GOOGLE