Re: IUSR trying to run cmd.exe... who is it?

From: Agustin (agustinchernitsky-SPAM@hotmail.com)
Date: 12/26/02


From: "Agustin" <agustinchernitsky-SPAM@hotmail.com>
Date: Thu, 26 Dec 2002 13:00:08 -0300


Well,

It seems it was a CGI script trying to run a SENDMAIL. I am checking that
now...

Thanks for everything!

"BB" <Bernard_at_3exp.com> wrote in message
news:uX5ZAd8qCHA.392@TK2MSFTNGP12...
> Nothing in IIS Log ? if you have urlscan, check urlscanxxxx.log.
> Any idea what's process id 2704. anything in event log ?
>
> Ensure your server is up to date. refer
> www.microsoft.com/security/
> also can refer
> http://securityadmin.info/faq.htm#harden
>
> Rgds.
>
>
> "Agustin Chernitsky" <agustinchernitskyNOSPAM@hotmail.com> wrote in
message
> news:ulY7aW6qCHA.2372@TK2MSFTNGP12...
> > Hi guys,
> >
> > For security reasons, I removed permissions from many files in win2k
> system
> > and added auditting to them. I keep getting this audit event (sometimes
3
> > times in a day. others 10 times in a day, all in a row) :
> >
> > <<<<
> > Event Type: Failure Audit
> > Event Source: Security
> > Event Category: Object Access
> > Event ID: 560
> > Date: 23/12/2002
> > Time: 09:33:03 p.m.
> > User: WWW01\IUSR_VGSVR
> > Computer: WWW01
> > Description:
> > Object Open:
> > Object Server: Security
> > Object Type: File
> > Object Name: C:\WINNT\system32\CMD.EXE
> > New Handle ID: -
> > Operation ID: {0,139507346}
> > Process ID: 2704
> > Primary User Name: IUSR_VGSVR
> > Primary Domain: WWW01
> > Primary Logon ID: (0x0,0x12BEC)
> > Client User Name: -
> > Client Domain: -
> > Client Logon ID: -
> > Accesses SYNCHRONIZE
> > Execute/Traverse
> >
> > Privileges -
> > >>>>
> >
> > It seems like one of my sites is trying to execute something with the
> shell.
> > I don't belive it's a hacker or code red (I have up to SP3 installed).
> >
> > I searched all the logs for this month (looking for the text cmd) but
> > nothing. So this narrows the search to my users code.
> >
> > Any ideas on how to detect which web site is doing this??
> >
> > Thanks!!
> >
> > Agustin.
> >
> >
> >
> >
>



Relevant Pages

  • Re: IUSR trying to run cmd.exe... who is it?
    ... > Nothing in IIS Log? ... I keep getting this audit event (sometimes ... >> Event Source: Security ... >> Any ideas on how to detect which web site is doing this?? ...
    (microsoft.public.inetserver.iis.security)
  • Re: WSUS Client not yet reported
    ... directory must be in a web site that listens to port 80. ... Microsoft Online Newsgroup Support ... This newsgroup only focuses on SBS technical issues. ... please help me gather IIS log and Metabase to me for further ...
    (microsoft.public.windows.server.sbs)
  • Re: ASP.NET Win2K and WinXP login problems
    ... Than restarted the IIS and tried to logon from Win2K ... I don't see any Errors in the Security (All Success ... Here is the log from IIS log file ...
    (microsoft.public.inetserver.iis)
  • STRANGE: Web Site Accessible by Some, Not Others
    ... access the web site. ... laptop and was able to get in. ... The web server is running: ... The following is a section of the IIS log, ...
    (microsoft.public.inetserver.iis.security)
  • Looking for Some Ideas...
    ... access the web site. ... laptop and was able to get in. ... The web server is running: ... The following is a section of the IIS log, ...
    (microsoft.public.inetserver.iis.security)