The Computer Emergency Response Team (CERG) recently revealed that the IIS6 WebDAV vulnerability, discovered last week by computer security expert Nikolaos Rangos, has been used in the attack. The vulnerability can view and upload files to IIS6 servers through a forged HTTP request. The attack exploited a vulnerability in Microsoft's handling of Unicode tokens.