Re: Strange problem with IIS and Denial of Service attack...

From: Larry (nospam_at_home.com)
Date: 07/30/03


Date: Wed, 30 Jul 2003 12:05:19 GMT

What's the IP address? Have you done a whois query to see which
Microsoft server it is talking to to see if there is an update or
patch fix? That's a lot of what you see going on during idle
periods....

Give us the "attacker" IP so we can find out what it is.

On 30 Jul 2003 00:12:02 -0700, justin_edmunds2001@yahoo.co.uk (Justin)
wrote:

>I've got an interesting problem with my webserver.
>
>CURRENT STATE
>Over the last two weeks my website and email server has been down as
>it seems to be attacked by an ICMP Echo Request flood. It always
>originates from a single IP address. The result is my machine is
>totally inaccessible whilst this is occurring.
>
>THE CLINCHER
>However, on investigating I've notice that if I use the server all is
>OK. The network is accessible and email are able to come in.
>If I leave the server for an hour or so, the attacking seems to start.
>As soon as I go back to the server, and open Internet Explorer (not
>just move the mouse as this has no effect) - the attacking will stop
>and the webserver and email services will again be accessible.
>
>CONCLUSION
>So it seems that as soon as IE is accessing the internet my server is
>accessible... Very strange - I seem to have some sort of trojan that
>only kicks in when there is no detected internet activity. Recently, I
>was able to stop the floods by leaving IE on a website (news.com.au)
>that refreshes itself automatically every minute. This is currently
>how I can stop the floods.
>
>* I have a Netgear firewall which only allows in HTTP and SMTP traffic
>for the webserver and Email server.
>* I have put ZoneAlarm on to try and trap the thing going out
>* I've tried a full virus scan with the latest form Norton Antivirus.
>
>Anyone seen this sort of thing before?
>
>Justin
>(Server running Win2k Server and IIS5 and latest hotfixes)

Larry W4CSC

"No, NO, Mr Spock! I said beam me down a WRENCH,
not a WENCH! KIRK OUT!"



Relevant Pages

  • Re: DNS newbie needs help
    ... > email server using IMAP. ... > the email pop and smtp servers to point at the email server ... you'll need to install and configure a DNS ... that Internet queries will use to resolve your external WAN IP. ...
    (microsoft.public.win2000.dns)
  • RE: SMTP delay
    ... If you choose to forward emails to the ISP's email server (smart ... To enable Message Tracking: ... Microsoft CSS Online Newsgroup Support ...
    (microsoft.public.windows.server.sbs)
  • New Linux server suggestions
    ... We are getting ready to replace our generic Linux email server (also ... for the most part (email setup, dns updates, etc...). ...
    (linux.redhat)
  • =?ISO-8859-1?Q?ADCD_based_SMTP_email?=
    ... My router setup allows me to get to the ADCD ... internet with no problems using the name server from my DSL connection. ... on the internet, when SMTP queues the mail to the external email server, it ... SMTP email from their home network? ...
    (bit.listserv.ibm-main)
  • Internet keeps often disconnecting after the initial email check in a Synchronize All
    ... a Synchronize All often disconnects from the internet after checking ... my only email server, but before checking any of my newsgroups servers. ...
    (microsoft.public.windows.vista.mail)