Microsoft denies fault in hacks
Microsoft is denying that a recent rash of Web server attacks are the company's fault.
In a blog posted late Friday night, Bill Sisk, of the Microsoft Security Response Center, wrote that the attacks are not due to any new or unknown security flaws in Internet Information Services or Microsoft SQL Server. Rather, he says, the attacks are made possible by SQL injection exploits and points Web developers to the company's list of best practices to prevent such attacks.
Ongoing attacks have affected half a million Web pages, compromising them so they serve up malware, according to several reports. The hacked sites include government sites in the U.K. and sites belonging to the United Nations.L33tdawg: The 'unknown security flaws in IIS and SQL Server' that Bill talks about is basically Cesar Cerrudo's 0-day presented in HITBSecConf2008 - Dubai.