IIS problems may not be Microsoft's fault
Independent security researchers agreed that Google Inc. was on the right track yesterday when it claimed that sites running Microsoft Corp.'s Web server are twice as likely to host hacker code than sites that rely on servers operating open-source software.
But they caution against jumping to conclusions.
"The vulnerability of the Web server [software] isn't the whole picture," said Zulfikar Ramzan, a senior principal researcher at Symantec Corp.'s security response group. "The administrator might not have configured it properly, or a third-party package on the server could have been compromised." According to Google's survey of 70,000 domains actively distributing malware or hosting browser exploits aiming for drive-by attacks, servers using Microsoft's Internet Information Service 5.0 or IIS 6.0 software were more than twice as likely to spew malicious code than servers running open-source Apache. Within the IIS results, 80% of the malware-hosting servers were running the most current version of the software, IIS 6.0.