as you learned in chapter3,internet information server is microsoft's web server
software.microsoft supplies IIS with the verions of its windows server operating systems
that are suitable for use in operating electronic commerce web sites.
In august 2001,microsoft faced an uncomfortable situation that many u.s.
manufacturing companies have experienced with recalled,defective products.microsoft
executive stood by at a new conference while a u.s. government official announced to
reporters that there was serious flaw in a microsoft product.the director of the FBI's
national infrastructure protection center was warning reporters that the code red
worm,which was spreading through the internet fof the third time in many weeks,
was a serious threat to the continued opration of the internet.
the code red worm exploits a vulnerability in the microsoft IIS web server software.
when the wrom was first identified,microsoft quickly made a patch available on its web site.
microsoft also announced that web server installtions that had kept current with all of
the updates and patches that microsoft had issued would not be to attack by the worm.
many iis users began to consider switching to other Web server software.
Gartner,Inc, a major IT consulting firm,recommended to its clients that
they seriously consider alternatives to IIS for their critical Web server installation
Many industry observers and sofware engineers agee that Microsoft was a victim of its own success.
It had created a very popular and complex piece of software. It is extremely difficult to ensure
that no bugs exist in complex software product, and the popularity of the software made it an
attractive target for cracker one worm could bring down many of the servers operating
on the internet. These two factors,plus the likelihood that many IIS servers
would not have all of the available security upgrades installed, combined to make it
an irresistible target for a worm cretor.
Microsoft has struggled to gain the confidence of large corporate IT departments
The company has worked hard to convince users that its operating system software is
reliable and trusworthy. For example, when Microsoft introduced version 7 of IIS in
2008,it announced that its architecture had been changed so that user could install
only the modules they needed to reduce the software's "attack surface."
The Code Red worm attack on its web server software was a major setback in it's
reputation-building effort.Since that attack , a number of security weaknesses have been
identified in IIS and patched by Microsoft. The news reports that inevitably accompany
these patches have created a continuing public relation issue for the company. you can
review the microsoft safety & security center through the web links to see how microsoft
deals with ongoing concerns that its software is secure in theface of attacks that are both regular and frequent.