IIS traffic

From: Mason, Samuel (smason_at_state.mt.us)
Date: 11/19/03

  • Next message: JimRuddy: "RE: Hiding MS SQL databases in Enterprise Manager"
    To: focus-ms@securityfocus.com
    Date: Wed, 19 Nov 2003 13:55:39 -0700
    
    

    While clearing out some information in our web filter I noticed some odd
    traffic: internal web server addresses showing up under different dns names.
    For instance in the Host Name field we see "sucks.freexxxxxvideo.com" and
    yet the IP comes up in our address range. Opening the traffic I find a DSL
    customer's IP from speakeasy.net. It looks like they are making what starts
    out as a legitimate request from our IIS 5.0 webserver and then redirect to
    whatever porn site they are after at the time.

    Looking at the IIS logs on the affected server I see nothing more than this
    to give me a clue:

    2003-11-05 12:44:26 66.93.24.88 - X.X.X.X 80 GET /Default.asp - 200
    sucks.freexxxxxvideo.com Mozilla/4.0 -

    Is this a common occurrence with IIS? How do we stop this from happening?

    Thanks for any help.

    Samuel Mason
    Information Technology Security Office
    State of Montana
     

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------


  • Next message: JimRuddy: "RE: Hiding MS SQL databases in Enterprise Manager"

    Relevant Pages

    • Re: IIS traffic
      ... is it cs-agent? ... Subject: IIS traffic ... While clearing out some information in our web filter I noticed some odd ... : traffic: internal web server addresses showing up under different dns ...
      (Focus-Microsoft)
    • Re: ASP.NET Development Server -> IIS
      ... From that point on, the VS.NET IDE will not use the internal web server, ... but will use IIS to open your pages. ... Okay, thanks. ...
      (microsoft.public.dotnet.framework.aspnet)
    • Re: ASP.NET configuration item not found
      ... Are you using the internal Web server for development or IIS? ... Yes the ASP.NETWebAdminFiles folder does exits ...
      (microsoft.public.dotnet.framework.aspnet)
    • Re: DNS Configuration Question
      ... > that will forward my wan ip address to an internal ip. ... > to access the website internally via the LAN it will not work. ... > a record in the DNS server to forward any request to the WAN ip from ... blank and give it the IP of the internal web server. ...
      (microsoft.public.win2000.dns)
    • Internal DNS Issue
      ... internal web server shop.compnayname.com and this works fine from outside of ... But we are unable to access it on our internal network, but if I do not use ... the public IP name assigned but use the internal server name it resolves. ... I know that I have to add something to DNS but not sure. ...
      (microsoft.public.windows.server.sbs)