Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

BA pulls IIS web servers offline in Code Red scare
Computing ^ | 3rd April 2002 | Network News staff

Posted on 04/04/2002 5:41:09 AM PST by colette_g

BA pulls IIS web servers offline in Code Red scare
By Network News staff [03-04-2002]

BA tightens IT security and dumps unauthorised Microsoft servers
BA has ditched 100 "unauthorised" web servers running Microsoft IIS from its network after fears the software could be a target for the Code Red virus.

The move came after the company found the web servers had been installed by staff "without the correct authorisation procedures".

"As part of our normal housekeeping procedures we launched an internal review of our use of Microsoft web servers," said a BA spokesman. "We are undertaking a project to remove the product where it has been installed without the correct authorisation procedures."

According to internet consultancy Netcraft, all BA websites currently visible from the internet run Netscape Enterprise 4.1 on Sun Solaris. The BA spokesman said all the IIS servers ran departmental intranets and it was not possible to view them externally "unless this is configured in our web access control infrastructure".

If an IIS-based server is not properly configured and patched, it is vulnerable to external attacks by hackers.

The Code Red virus exploits a buffer overflow vulnerability in an unpatched machine that could let an attacker gain complete control of an affected web server.

Richard Barber of security consultants Integralis said BA had felt secure because it had a policy of using non-Microsoft web servers. "People inside a company can set up their own web servers and if these servers go to the internet through the firewall at HTTP, they become visible," he said. "It is then fairly obvious from the outside of the network to hackers."

In future BA hopes to keep tabs on its infrastructure "by regular audits and reviews of web servers".

Microsoft declined to comment.



TOPICS: Extended News; News/Current Events; Technical; United Kingdom
KEYWORDS: ba; britishairways; iis; microsoft

1 posted on 04/04/2002 5:41:10 AM PST by colette_g
[ Post Reply | Private Reply | View Replies]

To: colette_g
What's BA?
2 posted on 04/04/2002 5:54:14 AM PST by BrooklynGOP
[ Post Reply | Private Reply | To 1 | View Replies]

To: BrooklynGOP
British Airways
3 posted on 04/04/2002 5:58:39 AM PST by lelio
[ Post Reply | Private Reply | To 2 | View Replies]

To: BrooklynGOP
Sorry, British Airways, UK's biggest airline.
4 posted on 04/04/2002 6:02:07 AM PST by colette_g
[ Post Reply | Private Reply | To 2 | View Replies]

To: colette_g, lelio
Ah! Well, isn't this IIS bug old already?
5 posted on 04/04/2002 6:06:11 AM PST by BrooklynGOP
[ Post Reply | Private Reply | To 4 | View Replies]

To: colette_g
OK, I'll bite. What is BA doing letting staff put up a hundred or so unauthorized web servers in the first place? You might get the idea that their "staff" was a little out of control and that this had little to do with Microsoft.
6 posted on 04/04/2002 6:11:32 AM PST by pt17
[ Post Reply | Private Reply | To 1 | View Replies]

To: pt17
I'm not a fan of Microsoft, but I agree this isn't their fault. Any web server that is set up by an inexperienced member of staff (whether IIS, Apache or whatever) is asking for trouble. But to let your stuff set up hundreds ???????!
7 posted on 04/04/2002 6:52:39 AM PST by colette_g
[ Post Reply | Private Reply | To 6 | View Replies]

To: pt17
When you install a server, it asks if you want IIS running. Some people just say Yes by default.
8 posted on 04/04/2002 6:54:18 AM PST by AppyPappy
[ Post Reply | Private Reply | To 6 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson