IIS 4.0 DOS attack?

From: Douglas R. Wilson (dallendoug_at_dallenhome.org)
Date: 07/19/01


running into a frustrating situation, and wondering if anyone has seen
anything like this before --

we have 2 servers on our network that keep having their w3svc crash out
every few minutes, like clockwork. just started a few hours ago. No
strange updates/patches/etc made in the past day or so, servers have
been running for a while -- access to lots of clients and developers
though.

We have several admins working on this -- sifting through logs, etc. So
far, no real anomalies in HTTP logs (no requests with large or weird
packets -- but one server has so many logs, haven't been able to go
through all of them yet) -- but a lot of bogus FTP attempts detected
right before this started happening (ie logins from same IP w/ bogus
login/pass on both servers). This could be total coincidence, or
pre-strike probe.

I know this is not a lot of info -- we are still gathering and
monitoring -- just wondering if this rang a bell with anyone.

TIA,

doug

-- 

Douglas R. Wilson

dallendoug_at_dallenhome.org



Relevant Pages

  • Re: 1058 and 1030 errors revisited
    ... from what I can see when I look at the event logs on all ... minutes on that client. ... I watched the Network Monitor on the server adapters this ... We have four servers to ...
    (microsoft.public.windows.group_policy)
  • Re: Systems all over the network are rebooting spontaneously at the same time!
    ... >> Now 13 servers were rebooted with the same error message. ... >> Again nothing showed up in event logs or firewall traffic ... >> No strange services are running and no tasks are scheduled. ... >> No strange network traffic can be found in the firewall ...
    (microsoft.public.win2000.general)
  • Re: Systems all over the network are rebooting spontaneously at the same time!
    ... > Now 13 servers were rebooted with the same error message. ... > Again nothing showed up in event logs or firewall traffic ... > No strange services are running and no tasks are scheduled. ... > No strange network traffic can be found in the firewall ...
    (microsoft.public.win2000.general)
  • Spontaneously reboots all over LAN
    ... across the entire network got the error code 128 on % ... Now 13 servers were rebooted with the same error message. ... Again nothing showed up in event logs or firewall traffic ... No strange services are running and no tasks are scheduled. ...
    (microsoft.public.win2000.general)
  • Various restarts all over LAN at the same time
    ... across the entire network got the error code 128 on % ... Now 13 servers were rebooted with the same error message. ... Again nothing showed up in event logs or firewall traffic ... No strange services are running and no tasks are scheduled. ...
    (microsoft.public.win2000.networking)