When Panda Security first noted the infestation, it put the number of infected IIS servers at 282,000. Less than a day later, security firm F-Secure wrote its own
blog entry, putting the infestation at over 500,000.
Worse, these infestations don't come through seamy Web sites -- they are taking place in legitimate Web pages. A secretly embedded IFRAME (
define) redirects a user to another page, where identity-stealing malware is downloaded onto his or her computer. So even users who think they are staying clean are not safe.
InternetNews Realtime IT News - Half-Million IIS Servers Hit in Cyber Attack