8 ms·
New malware abuses Microsoft IIS feature to establish backdoor
- greatgib 4y agoIt's 2023, if you are still using IIS you are highly incompetent and you deserved to be rooted...
- sublinear 4y agoPeople use IIS?
- tenebrisalietum 4y agoI think Stackexchange does.
- Someone1234 4y agoIn 2009, they certainly did. Since then, they migrated to .Net "Core"[0] which can run on any OS/web-server. Per [0] they initially kept IIS, but once you're on .Net Core+ that certainly isn't a requirement and there may be good licensing or performance reasons to migrate (even with headless Windows Server/IIS). I did find an article from last year that said they still had a monolithic architecture and were still on-prem (as opposed to cloud/Azure). So, maybe, still on IIS? They certainly did for YEARS. [0] https://www.infoq.com/news/2020/04/Stack-Overflow-New-Architecture/ https://www.infoq.com/news/2020/04/Stack-Overflow-New-Archit...
- DoctorOW 4y agoThey're hiring people with Windows Server experience. They're at the very least somewhat IIS. Source: https://stackoverflow.co/company/work-here/4866168 https://stackoverflow.co/company/work-here/4866168
- CompuHacker 4y agoYeah! I run an unpatched IIS FTP server on Windows 10 from 2016. When FileZilla stopped connecting to it for reasons I can't even imagine, I enabled SSL using some slightly modified arcane commands I found on a forum post from 2011 to generate a self-signed certificate, convert it between two different formats, and finally use it to accept connections from only some of the still available FTP clients for Windows, which excluded Windows Explorer, but only some of the time. Why, should I not be using IIS?
- gerdesj 4y agoAhhh - hello DevOps!
- doubleg72 4y agoArcane commands? Sounds like a fairly typical process to me, and a fairly typical use case. We do something similar with our Avaya CM and phone configuration and backups.
- rbanffy 4y agoI hope this is humor. I really do.
- CompuHacker 4y agoI wish it was, as well. What should I be doing?
- thedougd 4y agoEven worse, some companies choose to ship software that require the use of IIS.
- robotnikman 4y agoYep. From what I've seen, usually it's a case of a company building something which uses it a long time ago, and not bothering to switch to an alternative because 'If it works don't fix it'. It may not be the newest and shiniest, but if it's working well then no need to move to something else.
- gerdesj 4y agoI have customers with DOS (6.2, so quite modern) controlling machines. I ended up wedging a Samba daemon between that and PCs running Windows 10. I mount the DOS box's share via mount.smbfs and re-export it via Samba. The machine is on a rather sparse VLAN! I have many other horrors on isolated VLANs across the UK to worry about ...
- calvinmorrison 4y agoAnd here's a great point to install a proxy web server like nginx, add rate limiting, filtering, whatever you want, at least the ancient IIS/whatever http server is not publically facing
- boston_clone 4y agoCarbonBlack App Control required it as of 2021 I believe.
- joenathanone 4y agoWhat's wrong with using IIS?
- louthy 4y agoNothing, it’s just standard tech snobbery
- alexjplant 4y agoIt's snobbery to have an opinion? In terms of both static and application web servers I've personally administered nginx, Apache, IIS, Tomcat, Wildfly and Websphere and mention them here in descending order of preference with regard to capability and DX. As you can see IIS falls squarely in the middle of the pack and is actually a distant third in my opinion. The only compelling reason to use it a decade ago was to host .NET applications in an officially-supported manner (and even then it meant contending with licensing, weird logging behavior, arcane MMC-controlled XML-based configuration, Windows Server itself, etc). In the age of .NET Core there's no reason at all.
- louthy 4y ago> It's snobbery to have an opinion? Of course not and I didn't say any such thing. The original comment "People use IIS?" is clearly a passive-aggressive dig at MS, its tech, and those that use it (as is so often the case in tech circles). It's quite pathetic and childish. If I misunderstood that, then I apologise to the author, but I'd argue it still adds nothing to the discourse even if it was asked honestly. It doesn't mean you can't hold an opinion on the relative merits of any one piece of tech. But this "my computer is better than your computer" immature schoolboy nonsense is pervasive in tech circles and is extremely tedious. I have no love for IIS, but it's a perfectly capable webserver and is clearly still used. The idea that the .NET world have all moved over to .NET Core is also a wishful one unfortunately, I still maintain my open-source libraries for the legacy framework as I know there's plenty of places that can't just 'flip the switch' to .NET Core. It's not quite as bad as Python's V3 moment, but it's up there.
- tombert 4y agoI used to work for a .NET shop (pre .NET Core) doing F#, and we used IIS. In the company Slack, I said something like "Serious question; is there something that IIS does better than something like Nginx or any other open source server?" One of the most senior engineers responded back with "crashing".
- DaiPlusPlus 4y agoIIS can be configured by non-expert users easily, and without necessarily compromising security, thanks to the well-designed (I’m being serious) administration tools that MS has (thankfully) not butchered-up over the past 15 years. It’s an “old-world” web-server (like Apache, etc) which defaults to “filesystem-first” which is great for quickly making a directory available on the web, and its architecture employing recyclable worker-processes (since IIS 6) with limited privileges gives it the performance benefits of in-proc code-execution (vs CGI/FastCGI) without the risk of a vuln compromising the entire web server. Oh, and HTTP.sys is pretty nice and fast too. I’ve never had reliability or crashing issues with IIS: if your worker-process goes down it means your application code has a crashing bug in it, not IIS. Yeah, nginx is nice - but is also a relatively recent tool (since 2004, I didn’t start seeing people prefer it for projects until after NodeJS gave them a reason to use it - so around 10 years ago). While nginx supports Windows, there’s a big fat caution saying it’s performance is sub-par still: https://nginx.org/en/docs/windows.html https://nginx.org/en/docs/windows.html So if you’re on Windows - because you’re a (non-Linux) .NET shop, or want/need to run on on-prem Windows Server boxes (especially SMB scenarios) it just makes sense to use IIS: it’s already there and certainly is not an underperforming, insecure, or otherwise “bad” web-server.
- ocdtrekkie 4y agoIt's usually the right choice if the software runs on a Windows host. Why add a whole bunch of third party problems on top? A lot of enterprise software is built in .NET for Windows, and as the expectation of web-based UIs for said software has increased... honestly I'd be surprised if IIS usage wasn't increasing in overall uses (though not in market share, for certain).
- sebazzz 4y agoOP is obviously in some kind of bubble. IIS isn't as used as much as it used to be but it is still used a lot and not the COBOL of Web servers.
- pram 4y agoUnironically: the fact that Microsoft has spent millions of man-hours building a complete alternative server ecosystem to UNIX/Linux continually blows my mind. Web servers, containers, virtualization, databases, languages, automation, security, etc. It's like NIH maximalism.
- jiggawatts 4y agoConversely, from the perspective of people that started with computers in the 1990s, it's bizarre how Linux keeps failing to copy Windows. At one point something like 95% of PCs were Windows, and the rest were mostly Apple Macs. Similarly in the server space, you would be surprised to hear that the majority of servers were Windows for quite a while. Note that I didn't say web servers, because not all the world is HTTP. There is still no equivalent to Microsoft Exchange, Group Policy, Enterprise PKI, and a bunch of other things in the Linux world. SAMBA copies Active Directory, but it's a direct clone, not a unique product. Not to mention that SQL Server isn't somehow "copying" UNIX. Its performance and feature set blows most of the open-source databases out of the water, with only Postgres having superior features (but not performance). Microsoft essentially invented OLAP with SQL Analysis Services, and they still have the most popular products in that space, such as Power BI. Etc...
- tester756 4y ago>Not to mention that SQL Server isn't somehow "copying" UNIX. Its performance and feature set blows most of the open-source databases out of the water, with only Postgres having superior features (but not performance). The tooling around SQL Server is decent
- pram 4y agoIf we're talking about the 1990s, SQL Server/Sybase ran on UNIX. Not to mention it's just a fork of Ingres lol
- the8472 4y ago> There is still no equivalent to Microsoft Exchange, Group Policy, Enterprise PKI, and a bunch of other things in the Linux world. Which also means fewer attack vectors.
- enfaun 4y agocertainly, working as an intern and they use IIS for serving Java webapps with Resin, honestly not surprised for enterprise applications that runs on Windows Server
- scarface74 4y agohttps://w3techs.com/technologies/details/ws-microsoftiis https://w3techs.com/technologies/details/ws-microsoftiis
- unxdfa 4y agoYes. It’s pretty unavoidable if you have the usual corporate behemoth ASP.Net ball and chain which has been dragged along begrudgingly for the last 20 years. And no it’s not going to be ported to .Net Core for ages because it has some proprietary component or library plugged into it and the vendor ceased to exist ten years ago and your entire business relies on it being patched by a involuntary black hat with mono Cecil to remove the licensing code. Plus everyone who wrote it is either dead or left so even small changes require a week of reverse engineering.
- jacquesm 4y agoI had the weirdest experience recently. A tech stack with IIS on the front, Linux in the middle and MSSQL on the back. I still don't get it.
- traceroute66 4y agoIIS = It Is Shit.
- kneebonian 4y ago[flagged]
- technion 4y agoWhat's described here is no different to a malicious nginx or Apache module, like this one from eight years ago: https://github.com/ChristianPapathanasiou/apache-rootkit https://github.com/ChristianPapathanasiou/apache-rootkit
- jimbobimbo 4y agoFTA: "In order to use this technique, an attacker needs to gain access to the Windows system running the IIS server by some other means. In this particular case, it is unclear how this access was achieved." See also "It rather involved being on the other side of this airtight hatchway" series by Raymond Chen: https://devblogs.microsoft.com/oldnewthing/20181219-00/?p=100515 https://devblogs.microsoft.com/oldnewthing/20181219-00/?p=10... https://devblogs.microsoft.com/oldnewthing/20211207-00/?p=106004 https://devblogs.microsoft.com/oldnewthing/20211207-00/?p=10...
- gerdesj 4y ago"it is unclear how this access was achieved" Not a good line in a write up like this. Windows does write n store an awful lot of logs by default. However thanks to circular logging with log sizes from the 1990s on critical logs, you can easily lose information. I can't remember what the defaults are (connects to 2016 AD DC) ... 20Mb for %SystemRoot%\System32\Winevt\Logs\Security.evtx . On a tiddly setup like mine (20 odd users), that will last ... less than a day. I ship the logs elsewhere for proper evaluation etc but 20Mb? Yes, you can fiddle with the default sizes via group policy and you probably should but 20Mb really is off of the 1990s. OK so all the "core" logs seem to be 20Mb each and there are the rest under /Microsoft/Windows with varying sizes. I probably ought to look at what a PC logs these days - probably the same silly sizes.
- Dylan16807 4y agoMy desktop has a 20MB security log that goes back 16 days, which seems like enough. If anything, stop spamming tens to hundreds of duplicate messages when credentials are read or group membership is enumerated. System has 8 months, application has 10 months, and setup has 26 months.
- gerdesj 4y agoYes (20Mb), but so do AD DCs which is frankly lazy on MS dev's part. If a DC is such a big deal that it requires rather more cash to buy than a "workstation" edition of Windows, then I'd like to see more attention to detail. By contrast a Linux box running systemd/journald by default will leave 10% disc space free when logging. That's enough to keep a filesystem honest! 20Mb on a DC - even one for a small site like mine will cycle quite often. I really recommend that you extend your logs to cover six months or more. It will cost you maybe a gigabyte or 10. Very little these days (my first HD was 20MB, yes: megabytes). However if you need to get some details from the past - very handy.
- danielodievich 4y agoNobody sane runs FREB at full prod load on public sites. It's not installed by default. It is highly useful for troubleshooting but not at production traffic. Seems like if you're inside IIS already by some mystic hack you already own the space.
- Someone1234 4y agoThis malware is enabling FREB then injecting malware into it. The point is to hide the exploitation better than simply injecting a custom module. You don't need to be running FREB previously. Plus I don't find the "nobody does [XYZ]" when talking about a supported feature of a popular product reassuring, there's always a somebody or the feature would have been removed since it costs money to support and maintain it.
- Dwedit 4y agoSo in other words, this is something that someone has to run on the computer, then it injects itself into IIS. Not a remote vulnerability, just an entry point for monitoring HTTP requests once you have code execution in there.