Re: Inetinfo CPU Utilization

From: Karl Levinson [x y] mvp (levinson_k@excite.com)
Date: 01/16/03


From: "Karl Levinson [x y] mvp" <levinson_k@excite.com>
Date: Wed, 15 Jan 2003 21:15:26 -0500

Could be a worm, or a scan. Check your firewall logs and/or your URLScan
logs and/or your IIS logs. If you have none of those, you better fix that
right quick. There are even free firewalls, even www.sygate.com
Installing a sniffer might help you look and see if network traffic is
causing this:

http://securityadmin.info/faq.htm#sniffer
http://securityadmin.info/faq.htm#firewall

Here are some things to do to look for signs of hacking:

http://securityadmin.info/faq.htm#hacked
http://securityadmin.info/faq.htm#harden

"Hector" <h_ramir@hotmail.com> wrote in message
news:6cf301c2bcf9$ba1126c0$cef82ecf@TK2MSFTNGXA08...
> Anyone have issues with ineinfo CPU utilization spikne
> around 90% for a couple of hours, then go back down. This
> is an Exchange server 2000
>
> Any insights or thoughts on what to look for, ports,
> security threat, anyone lese have same issue?



Relevant Pages

  • Full Plate of Crow
    ... Subject: Full Plate of Crow ... identifying a Code Red attack are two differant things entirely. ... are basing your attack stats off of firewall logs or simple access list ... firewall logs, not IDS logs. ...
    (Incidents)
  • Re: possible rooted systems
    ... Check the firewall logs for outbound and inbound connections on non standard ... Once you do that check standard ports. ... Either way check the logs on the firewall for abnormal usage (you should know ...
    (Security-Basics)
  • Re: catching a hacker?
    ... Well I hope it is from outside of your network. ... Another thing to try is to check your logs and your firewall logs to see if ... the firewall and server are synched time wise to make that effective. ...
    (microsoft.public.win2000.security)
  • Re: Inetinfo CPU Utilization
    ... > Thanks Karl. ... Check your firewall logs ... >>logs and/or your IIS logs. ... >>> security threat, ...
    (microsoft.public.inetserver.iis.security)
  • Re: Hiding Source Network Address
    ... the security log if auditing of logon events is enabled. ... security logs with the firewall logs to find the information that you need. ... The Windows ...
    (microsoft.public.windows.server.security)