Microsoft is committed to helping customers keep their information safe. We are currently working with law enforcement and industry partners to identify the individuals or entities responsible for a new Internet attack, known as Download.Ject, and bring those responsible for this criminal act to justice.
On Thursday, June 24, at 4:00 p.m. PDT, Microsoft responded to reports that some enterprise customers running un-patched versions of IIS 5.0 (Internet Information Services), a component of Windows 2000 Server, were being targeted by malicious code, known as Download.Ject. More information is available at: http://www.microsoft.com/downloadject. This site will be updated as new information becomes available.
Microsoft's security response teams are dedicated to analyzing, resolving and communicating progress to customers in a timely manner. It is important to note that at this time Microsoft is not aware of widespread customer impact based on Download.Ject. Microsoft has confirmed with its partners that this attack is not a "worm" or virus-in other words, this attack is a targeted manual attack by individuals or entities towards a specific server.
Microsoft is working with Internet service provider partners worldwide to shut down the malicious URLs. The primary Web site of attack was located in Russia and was taken offline Thursday evening, June 24. In addition, MSN is scanning for and blocking malicious URLs.
|