News

  • Home > News

        Security alert: Download.ject impacts XP Embedded webservers

        Doug | Date: Jun 28, 2004 | Comments: 1



        Microsoft has issued a security alert that applies to Windows XP and XP Embedded based systems and devices running the Internet Information Services (IIS) webserver. Microsoft says the attack is not a "worm" or virus, but is instead a "targeted manual attack by individuals or entities towards a specific server."




        Last week, Microsoft responded to reports that some enterprise customers running IIS 5.0, a component of Windows 2000 Server, were being targeted by malicious code, known as Download.Ject (a.k.a. JS.Scob.Trojan, Scob, and JS.Toofeer). Download.Ject is believed to be the work of spammers looking to create a network of compliant PCs that can be used as proxies to spread junk mail.

        "We are finding that devices running IIS are possibly being compromised and being used to attempt to infect Internet Explorer users with malicious code," Microsoft said.

        Internet service providers and law enforcement, working together with Microsoft, identified the origination point of the attack in Russia, and shut it down on Thursday, June 24, according to Microsoft.

        Microsoft advises developers running IIS 5.0 on a Windows XP or XP Embedded based device to make sure they have Security Update MS04-011 applied to their device. The update is available both on the OEM Secure Site and on the Download Center. The company also advises all users of Internet Explorer to be sure that they have installed the latest security updates and to utilize high security settings.



        Related stories: