Re: NImda/Code Red IIS log analysis questions

From: Adrien de Beaupre (adriendb@-nospam-magi.com)
Date: 12/20/01


From: "Adrien de Beaupre" <adriendb@-nospam-magi.com>
Date: Thu, 20 Dec 2001 10:14:31 -0500

It is not a good idea to trust a server that may have been compromised:

Generic quick and dirty incident handling procedure:

Get help.
Take the system off the network.
Backup all data.
Blow away the operating system.
Re-install from scratch.
Apply ALL service packs and hot-fixes.
Harden the server.
Restore data.
Test the server, run a vulnerability assessment
Return server to the network.

Adrien de Beaupre, A+/Network+/MCP/MCSE/MCT
Brainbench MVP for Networking Concepts
http://www.brainbench.com
"The problem with trouble-shooting is, sometimes trouble shoots back!"

<Jeff Cochran> wrote in message
news:3c22d7c4.235910501@news.supernews.com...
> >That first URL was "/scripts/root.exe?/c+dir /c+dir 200 -" and the
> >result was 200, meaning the request was succesful. What happened
> >here? What did IIS do? What action occurs when root.exe is run with
> >those specific parameters ? Is this harmful, did something bad
> >happen? Should I reformat my machine?
>
> Try here:
>
> http://www.iisfaq.com/
>
> Jeff



Relevant Pages

  • Re: Fully parallel Scheme-based language w/ evaluator
    ... Windows Server 2003 and networks in simple - and irreverent - terms. ... If networking really is a big deal, ... Concepts and Terminology in Part I, and The Design and Deployment of Network ...
    (comp.lang.misc)
  • Re: Outgoing POP3 email missing/lost/not received
    ... Funny thing is that I have had this ISP for 8 years and it has always been ... It looks like when you last ran CEICW, you set the ISP's mail server to: ... Internet Connection Wizard. ... After the wizard completes, the following network connection ...
    (microsoft.public.windows.server.sbs)
  • Re: Logon Server Unavailable
    ... There are currently no logon servers available to service ... You use a office laptop to connect the office VPN, when you map a network ... you may receive this message: "This account is the ... The server is not configured for transactions"> "A domain controller for your domain could not be contacted" ...
    (microsoft.public.windows.server.general)
  • Re: Logon Server Unavailable
    ... There are currently no logon servers available to service ... You use a office laptop to connect the office VPN, when you map a network ... you may receive this message: "This account is the ... The server is not configured for transactions"> "A domain controller for your domain could not be contacted" ...
    (microsoft.public.windows.server.dns)
  • Re: Logon Server Unavailable
    ... There are currently no logon servers available to service ... You use a office laptop to connect the office VPN, when you map a network ... you may receive this message: "This account is the ... The server is not configured for transactions"> "A domain controller for your domain could not be contacted" ...
    (microsoft.public.windows.server.networking)