A Japanese hacker has surreptitiously posted a program that could exploit a recently discovered hole in Microsoft Web server software, giving remote attackers complete control of vulnerable servers. The hacking script was posted last week on the GeoCities home page of a Japanese hacker. The code could potentially exploit a flaw in Microsoft's Internet Information Server (IIS). An IIS component doesn't check for buffer overruns, potentially enabling a hacker to gain full, system-level control of a server. "It is a very serious vulnerability--it's important to install the relevant patches as there are scumbags out there who will write programs to exploit these vulnerabilities," said Graham Cluley, senior technical consultant at antivirus software maker Sophos.
|