Suspicious URLScan.log

From: Michael Pruss (pruss@wissner.com)
Date: 09/10/02


Date: 10 Sep 2002 07:43:39 -0000
From: Michael Pruss <pruss@wissner.com>
To: focus-ms@securityfocus.com


('binary' encoding is not supported, stored as-is)

I use URLScan on a IIS 5. I found some strange behaviour in the Logfile of
URLScan. There are several startup-messages in a short interval but at
that time the server has not been restarted.

[09-05-2002 - 21:39:32] ---------------- Initializing
UrlScan.log ----------------
[09-05-2002 - 21:39:32] -- Filter initialization time: [09-
05-2002 - 21:39:32] --
[09-05-2002 - 21:39:32] ---------------- UrlScan.dll
Initializing ----------------

....

[09-05-2002 - 21:44:12] ---------------- Initializing
UrlScan.log ----------------
[09-05-2002 - 21:44:12] -- Filter initialization time: [09-
05-2002 - 21:44:12] --
[09-05-2002 - 21:44:12] ---------------- UrlScan.dll
Initializing ----------------

....

[09-05-2002 - 21:44:19] ---------------- Initializing
UrlScan.log ----------------
[09-05-2002 - 21:44:19] -- Filter initialization time: [09-
05-2002 - 21:44:19] --
[09-05-2002 - 21:44:19] ---------------- UrlScan.dll
Initializing ----------------

Can somebody tell me if the URLScan tool does an automatic restart in some
cases or if there is trouble ahead and somebody found a vulnerability in
that tool. The server has been killed shortly before that. After i
hardened the system this strange behavior occured but the server is still
alive.

Thanks
Michael


Quantcast