Re: Accessing mail from the web

From: Paul Schmehl (pauls@utdallas.edu)
Date: 08/18/01


Message-ID: <03e801c12795$4dc74580$220a400a@officeeagle>
From: "Paul Schmehl" <pauls@utdallas.edu>
To: "bonnie temple" <btemple@nglantz.com>, <security-basics@securityfocus.com>, <focus-ms@securityfocus.com>
Subject: Re: Accessing mail from the web
Date: Fri, 17 Aug 2001 22:10:52 -0500


----- Original Message -----
From: "bonnie temple" <btemple@nglantz.com>
To: <security-basics@securityfocus.com>; <focus-ms@securityfocus.com>
Sent: Friday, August 17, 2001 12:08 PM
Subject: RE: Accessing mail from the web

Is that why I still have default.ida XXXXXXXXXXXXXXXXXXXXXX lines in my
IIS logs after applying the Aug.15 patch?

Code Red never gets logged. The fact that you're seeing it in your logs
means it isn't working on your box. If it was, you wouldn't have anything
in the logs.

And what exactly does that line mean opposed to ...default.ida
NNNNNNNNNNNN

XXXX is Code Red II, which plants the explorer.exe trojan in the root of the
boot drive and a renamed copy of cmd.exe (root.exe) in the /Scripts
directory.

NNNN is Code Red I, which just defaces a web page. (Of course both also
launch multithreaded attacks against other IPs.)

Paul Schmehl pauls@utdallas.edu
Supervisor, Support Services
University of Texas at Dallas
AVIEN Founding Member



Relevant Pages

  • Re: Hacking attempts?
    ... Windows logs logon type 3 in most cases when you access a computer from elsewhere on the network. ... One of the most common sources of logon events with logon type 3 is connections to shared folders or printers. ... You can use the IIS logs to track down the ip addressthat are attempting unauthorized login. ...
    (microsoft.public.windows.server.sbs)
  • Re: hack attempts howto find ip
    ... IP logging is not offered until Windows XP with ICF firewall ... logs if you have, say, an FTP or NetBIOS attack. ... show up in the IIS logs. ...
    (microsoft.public.inetserver.iis.security)
  • Re: Out of Office Not working - BUG???
    ... This shows up in my IIS Logs: ... ConfigExceptionInfo ... ErrorCode The operation completed successfully. ...
    (microsoft.public.exchange.setup)
  • Out of Office Not working - BUG???
    ... This shows up in my IIS Logs: ... ConfigExceptionInfo ... ErrorCode The operation completed successfully. ...
    (microsoft.public.exchange.setup)
  • Re: How/Where do I check the most frequently used Search words?
    ... Or getting the logs into SQL using log parser for example. ... I do not recommend you try and extract the IIS logs straight into a SQL ... Get the IIS logs created on the WFE server and then use Log Parser ...
    (microsoft.public.sharepoint.portalserver)

Quantcast