Re: Security Scan on IIS shows files and folders

From: Jeff Cochran (jcochran)
Date: 08/16/02


From: jcochran at naplesgov dot com (Jeff Cochran)
Date: Fri, 16 Aug 2002 16:52:26 GMT


>Recently our comapny had a Professional Security Scan done one of our
>production web sites. We are running Windows 2000 SP2 (with all
>up-to-date patches), IIS 5.
>
>When they conducted the security scan, they told us we had many files
>with ".old or.bak" extensions. They also viewed the contents of a
>folder called "_test" on the site (off the wwwroot).
>
>My question, since they will not tell us, is; How are they viewing
>these files????

Why would anyone hire a "security scan" that didn't tell them how it
was done, and hopefully, how to fix the hole?

>How can they see folders "_xxxx" and files with "old" extensions on
>the Hard Drive.
>
>Directory browsing is turned off, so that's not it!
>
>We took our server offline until we can determine what the heck is
>causing this..

What do your firewall, FTP and IIS logs show from the time period of
the scan?

Jeff



Relevant Pages

  • RE: IIS 5 Patches
    ... The IIS April Security Rollup is one of the most important packages to have ... way to check whether you have all available patches is to install and run ...
    (microsoft.public.inetserver.iis.security)
  • Re: been hit by hacker, servudaemon installed
    ... security patching on iis 4.0 ... security fixes into the new version. ... >install all service packs and patches from Microsoft, ... >>>Windows, Apache, you name it. ...
    (microsoft.public.inetserver.iis.security)
  • Re: been hit by hacker, servudaemon installed
    ... security patching on iis 4.0 ... security fixes into the new version. ... :>install all service packs and patches from Microsoft, ... :>>>Windows, Apache, you name it. ...
    (microsoft.public.inetserver.iis.security)
  • Re: Mac Server Hacked In Less Than 6 Hours
    ... Windows has RAS, and for it is built in since NT 3.1 ... | A typical IIS box and this Mac are not the same thing so the comparison ... IIS has been subject to quite a few bugs and so have ... Security isn't a proprietary attribute. ...
    (sci.crypt)
  • Re: DCOM calls fails - access denied
    ... That's exactly how I understood the ASP.NET security. ... But why does one configuration work but not the other? ... should get the token from IIS. ... If you set there a domain account, ...
    (microsoft.public.dotnet.framework.aspnet.security)