<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.iis.net/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:cs="http://blogs.iis.net/"><channel><title>BillS IIS Blog : Security</title><link>http://blogs.iis.net/bills/archive/tags/Security/default.aspx</link><description>Tags: Security</description><dc:language>en</dc:language><generator>CommunityServer 2007 SP1 (Build: 20510.895)</generator><item><title>Why IIS7? Top 12 cool features…</title><link>http://blogs.iis.net/bills/archive/2008/11/20/why-iis7-top-12-cool-features.aspx</link><pubDate>Fri, 21 Nov 2008 04:13:45 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:2759317</guid><dc:creator>bills</dc:creator><slash:comments>2</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.iis.net/bills/rsscomments.aspx?PostID=2759317</wfw:commentRss><comments>http://blogs.iis.net/bills/archive/2008/11/20/why-iis7-top-12-cool-features.aspx#comments</comments><description>&lt;p&gt;Every time I talk with customers in meetings or at conferences I’m struck by how many cool amazing new capabilities IIS7 has.&amp;#160; I can go on for literally hours talking about the new features and benefits, and showing demos.&amp;#160; And with each new &lt;a href="http://www.iis.net/extensions"&gt;IIS7 Extension&lt;/a&gt;, the list of new features just gets bigger and bigger.&amp;#160; A few months ago I realized we didn’t have the top list of features written up anywhere, and so we started the process of distilling down the list to the top 10.&amp;#160; We almost made it!&amp;#160; We ended up with the top 12 reasons you should get IIS7 today.&amp;#160; Check them out here:&lt;/p&gt;  &lt;p&gt;&lt;a title="http://www.iis.net/getstarted" href="http://www.iis.net/getstarted"&gt;http://www.iis.net/getstarted&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Over the next few weeks we’ll be adding a cool demo for each of the reasons to show the features in action.&amp;#160; Be sure to check back soon!&lt;/p&gt;&lt;img src="http://blogs.iis.net/aggbug.aspx?PostID=2759317" width="1" height="1"&gt;</description><category domain="http://blogs.iis.net/bills/archive/tags/IIS7/default.aspx">IIS7</category><category domain="http://blogs.iis.net/bills/archive/tags/ASP.NET/default.aspx">ASP.NET</category><category domain="http://blogs.iis.net/bills/archive/tags/Extensibility/default.aspx">Extensibility</category><category domain="http://blogs.iis.net/bills/archive/tags/Administration/default.aspx">Administration</category><category domain="http://blogs.iis.net/bills/archive/tags/Troubleshooting/default.aspx">Troubleshooting</category><category domain="http://blogs.iis.net/bills/archive/tags/IIS+News+Item/default.aspx">IIS News Item</category><category domain="http://blogs.iis.net/bills/archive/tags/Developers/default.aspx">Developers</category><category domain="http://blogs.iis.net/bills/archive/tags/Performance/default.aspx">Performance</category><category domain="http://blogs.iis.net/bills/archive/tags/Videos/default.aspx">Videos</category><category domain="http://blogs.iis.net/bills/archive/tags/Media/default.aspx">Media</category><category domain="http://blogs.iis.net/bills/archive/tags/Administrators/default.aspx">Administrators</category><category domain="http://blogs.iis.net/bills/archive/tags/Configuration/default.aspx">Configuration</category><category domain="http://blogs.iis.net/bills/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.iis.net/bills/archive/tags/Deployment/default.aspx">Deployment</category></item><item><title>Find New IIS7 Extensions at http://www.iis.net/extensions/</title><link>http://blogs.iis.net/bills/archive/2008/11/11/find-new-iis7-extensions-at-http-www-iis-net-extensions.aspx</link><pubDate>Tue, 11 Nov 2008 22:55:00 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:2739094</guid><dc:creator>bills</dc:creator><slash:comments>7</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.iis.net/bills/rsscomments.aspx?PostID=2739094</wfw:commentRss><comments>http://blogs.iis.net/bills/archive/2008/11/11/find-new-iis7-extensions-at-http-www-iis-net-extensions.aspx#comments</comments><description>&lt;P&gt;I’m happy to announce that IIS7 Extensions have found their home at &lt;A href="http://www.iis.net/extensions"&gt;http://www.iis.net/extensions&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;Every since IIS7 shipped 9 months ago, the IIS team has been cranking away adding new features to the platform.&amp;nbsp; Last time I blogged about &lt;A href="http://blogs.iis.net/bills/archive/2008/06/02/how-iis-ships-software.aspx" mce_href="http://blogs.iis.net/bills/archive/2008/06/02/how-iis-ships-software.aspx"&gt;how we do this&lt;/A&gt;, I realized we didn’t have a single place to learn about all of them, so I kicked off an effort within the team to create this.&amp;nbsp; Now that the pages are up, it is amazing to see how many new capabilities are already available on top of IIS7…which all by itself had more new features than any other IIS release in the history of the product.&amp;nbsp; It is a testament to not only the ingenuity and hard work of the IIS team, but a real validation that IIS7 is not just a Web server, it is a server platform.&amp;nbsp; All of these new features are built on top of public extensibility points that any developer can use, and provide a seamless runtime, configuration and administration experience that looks and feels like they were built into the product to begin with!&amp;nbsp; Here they are:&lt;/P&gt;
&lt;P&gt;Landing page:&amp;nbsp; &lt;A href="http://www.iis.net/extensions"&gt;http://www.iis.net/extensions&lt;/A&gt; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A title=http://www.iis.net/AdministrationPack href="http://www.iis.net/AdministrationPack" mce_href="http://www.iis.net/AdministrationPack"&gt;http://www.iis.net/AdministrationPack&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A title=http://www.iis.net/ApplicationRequestRouting href="http://www.iis.net/ApplicationRequestRouting" mce_href="http://www.iis.net/ApplicationRequestRouting"&gt;http://www.iis.net/ApplicationRequestRouting&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A title=http://www.iis.net/BitRateThrottling href="http://www.iis.net/BitRateThrottling" mce_href="http://www.iis.net/BitRateThrottling"&gt;http://www.iis.net/BitRateThrottling&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A title=http://www.iis.net/DatabaseManager href="http://www.iis.net/DatabaseManager" mce_href="http://www.iis.net/DatabaseManager"&gt;http://www.iis.net/DatabaseManager&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A title=http://www.iis.net/FTP href="http://www.iis.net/FTP" mce_href="http://www.iis.net/FTP"&gt;http://www.iis.net/FTP&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A title=http://www.iis.net/IISManager href="http://www.iis.net/IISManager" mce_href="http://www.iis.net/IISManager"&gt;http://www.iis.net/IISManager&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A title=http://www.iis.net/PowerShell href="http://www.iis.net/PowerShell" mce_href="http://www.iis.net/PowerShell"&gt;http://www.iis.net/PowerShell&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A title=http://www.iis.net/SmoothStreaming href="http://www.iis.net/SmoothStreaming" mce_href="http://www.iis.net/SmoothStreaming"&gt;http://www.iis.net/SmoothStreaming&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A title=http://www.iis.net/URLRewrite href="http://www.iis.net/URLRewrite" mce_href="http://www.iis.net/URLRewrite"&gt;http://www.iis.net/URLRewrite&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A title=http://www.iis.net/UrlScan href="http://www.iis.net/UrlScan" mce_href="http://www.iis.net/UrlScan"&gt;http://www.iis.net/UrlScan&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A title=http://www.iis.net/WebDeploymentTool href="http://www.iis.net/WebDeploymentTool" mce_href="http://www.iis.net/WebDeploymentTool"&gt;http://www.iis.net/WebDeploymentTool&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A title=http://www.iis.net/WebPlaylists href="http://www.iis.net/WebPlaylists" mce_href="http://www.iis.net/WebPlaylists"&gt;http://www.iis.net/WebPlaylists&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A title=http://www.iis.net/WebDAV href="http://www.iis.net/WebDAV" mce_href="http://www.iis.net/WebDAV"&gt;http://www.iis.net/WebDAV&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Check out the &lt;A href="http://www.iis.net/extensions" mce_href="http://www.iis.net/extensions"&gt;more than a dozen new features&lt;/A&gt; available today!&amp;nbsp; Over the next few weeks we’ll be adding video demos of each feature and more new content.&amp;nbsp; Stay tuned for many cool new features to come!&lt;/P&gt;&lt;img src="http://blogs.iis.net/aggbug.aspx?PostID=2739094" width="1" height="1"&gt;</description><category domain="http://blogs.iis.net/bills/archive/tags/IIS7/default.aspx">IIS7</category><category domain="http://blogs.iis.net/bills/archive/tags/ASP.NET/default.aspx">ASP.NET</category><category domain="http://blogs.iis.net/bills/archive/tags/PHP/default.aspx">PHP</category><category domain="http://blogs.iis.net/bills/archive/tags/Extensibility/default.aspx">Extensibility</category><category domain="http://blogs.iis.net/bills/archive/tags/IIS+News+Item/default.aspx">IIS News Item</category><category domain="http://blogs.iis.net/bills/archive/tags/Media/default.aspx">Media</category><category domain="http://blogs.iis.net/bills/archive/tags/FastCGI/default.aspx">FastCGI</category><category domain="http://blogs.iis.net/bills/archive/tags/Administrators/default.aspx">Administrators</category><category domain="http://blogs.iis.net/bills/archive/tags/Configuration/default.aspx">Configuration</category><category domain="http://blogs.iis.net/bills/archive/tags/Extensions/default.aspx">Extensions</category><category domain="http://blogs.iis.net/bills/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.iis.net/bills/archive/tags/URL+Rewrite/default.aspx">URL Rewrite</category><category domain="http://blogs.iis.net/bills/archive/tags/Deployment/default.aspx">Deployment</category></item><item><title>SQL Injection Attacks on IIS Web Servers</title><link>http://blogs.iis.net/bills/archive/2008/04/25/sql-injection-attacks-on-iis-web-servers.aspx</link><pubDate>Sat, 26 Apr 2008 04:33:14 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:2322388</guid><dc:creator>bills</dc:creator><slash:comments>105</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.iis.net/bills/rsscomments.aspx?PostID=2322388</wfw:commentRss><comments>http://blogs.iis.net/bills/archive/2008/04/25/sql-injection-attacks-on-iis-web-servers.aspx#comments</comments><description>&lt;p&gt;You may have seen &lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;taxonomyId=17&amp;amp;articleId=9080580&amp;amp;intsrc=hm_topic"&gt;recent&lt;/a&gt; &lt;a href="http://www.pcworld.com/article/id,145151-c,hackers/article.html"&gt;reports&lt;/a&gt; that have surfaced stating that web sites running on Microsoft&amp;#8217;s Internet Information Services (IIS) 6.0 have been compromised. These reports allude to a possible vulnerability in IIS or issues related to &lt;a href="http://www.microsoft.com/technet/security/advisory/951306.mspx"&gt;Security Advisory 951306&lt;/a&gt; which was released last week.&lt;/p&gt;  &lt;p&gt;Microsoft has investigated these reports and determined that the attacks are &lt;u&gt;not&lt;/u&gt; related to the recent &lt;a href="http://www.microsoft.com/technet/security/advisory/951306.mspx"&gt;Microsoft Security Advisory (951306)&lt;/a&gt; or &lt;u&gt;any&lt;/u&gt; &lt;u&gt;known&lt;/u&gt; &lt;u&gt;security&lt;/u&gt; &lt;u&gt;issues&lt;/u&gt; related to IIS 6.0, ASP, ASP.Net or Microsoft SQL technologies.&lt;/p&gt;  &lt;p&gt;Instead, attackers have crafted an automated attack that can take advantage of SQL injection vulnerabilities in web pages that do not follow security best practices for web application development. While these particular attacks are targeting sites hosted on IIS web servers, SQL injection vulnerabilities may exist on sites hosted on any platform.&amp;#160; More information on SQL injection attacks can be found &lt;a href="http://msdn2.microsoft.com/en-us/library/ms161953.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://msdn2.microsoft.com/en-us/library/bb671351.aspx"&gt;here&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;Guidance from Microsoft for web application development best practices can also be found on &lt;a href="http://msdn2.microsoft.com/en-us/library/ms994921.aspx"&gt;this MSDN page&lt;/a&gt;. Best practices guidelines that developers may follow to mitigate SQL injection, can be located &lt;a href="http://msdn2.microsoft.com/en-us/library/ms998271.aspx"&gt;here&lt;/a&gt;. As we continue to make progress in our investigation on this attack, we will provide updated guidance and information on the &lt;a href="http://www.iis.net/"&gt;IIS.net&lt;/a&gt; site. For the latest information on this issue, please subscribe or visit the &lt;a href="http://forums.iis.net/p/1149068/1868206.aspx"&gt;IIS security forum&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;For end-users, the investigation also shows no indication of an un-patched vulnerability in IIS, SQL Server, Internet Explorer or any other Microsoft client software, so we recommend customers apply the latest updates to be protected from these attacks.&lt;/p&gt;  &lt;p&gt;To further protect themselves from reported attacks, we encourage all customers to apply our most recent security updates to help ensure that their computers are protected from attempted criminal attacks. For more information about security updates, visit: &lt;a href="http://www.microsoft.com/protect"&gt;www.microsoft.com/protect&lt;/a&gt;. &lt;/p&gt;  &lt;p&gt;Anyone believed to have been affected can visit: &lt;a href="http://www.microsoft.com/protect/support/default.mspx"&gt;http://www.microsoft.com/protect/support/default.mspx&lt;/a&gt; and should contact the national law enforcement agency in their country.&amp;#160; Those in the United States can contact Customer Service and Support at no charge using the PC Safety hotline at 1-866-PCSAFETY.&amp;#160; Additionally, customers in the United States should contact their local FBI office or report their situation at: &lt;a href="http://www.ic3.gov"&gt;www.ic3.gov&lt;/a&gt;&lt;/p&gt;&lt;img src="http://blogs.iis.net/aggbug.aspx?PostID=2322388" width="1" height="1"&gt;</description><category domain="http://blogs.iis.net/bills/archive/tags/ASP.NET/default.aspx">ASP.NET</category><category domain="http://blogs.iis.net/bills/archive/tags/IIS+News+Item/default.aspx">IIS News Item</category><category domain="http://blogs.iis.net/bills/archive/tags/Developers/default.aspx">Developers</category><category domain="http://blogs.iis.net/bills/archive/tags/Administrators/default.aspx">Administrators</category><category domain="http://blogs.iis.net/bills/archive/tags/Security/default.aspx">Security</category></item></channel></rss>