Re: default.ida

From: Ken Reilly (kreilly_at_meathcoco.ie)
Date: 06/04/03


Date: Wed, 4 Jun 2003 17:53:14 +0100


Thanks Erik.

Where am I looking for these errors...in the same Firewall report, or logs
....?

Ken
"Erik" <erik@nospam.com> wrote in message
news:15d001c32ab7$972a0100$a501280a@phx.gbl...
>
> >-----Original Message-----
> >On my Firewall logs on a frequent basis I am getting the
> following
> >message as a destination:
> http://192.168.1.3/default.ida?. The IP address is
> >just a web server on a DMZ, but can anyone tell me the
> significance of the
> >"default.ida" file?
> > I'd appreciate any help!!
> > Ken
> >
> >
> >.
> >
>
> The default.ida is the file that Cod Red exploits. Your
> firewall is probably stopping the attack. Look for the
> 404 error, which would mean that your are OK. If it's
> getting a 200, then you may want to look at the server,
> which could be compromised.



Relevant Pages

  • Re: disconnect a hacker
    ... My Web server station is right next ... my attention divided by security concerns... ... see an IP connected to port 80, ... I've been forwarding my firewall logs to my ISP, ...
    (alt.computer.security)
  • Re: Firewall on server itself
    ... Perhaps the iptables could defend against an intruder who is already ... Firewall vender specific vulnerabilities ... >> be configured to protect the web server as well other computers on ... > The Gartner Group just put Neoteris in the top of its Magic Quadrant, ...
    (Security-Basics)
  • Re: [fw-wiz] Using SSL accelerators in firewalls
    ... It also depends on what you're using your SSL for, and how tightly you can couple ... your firewall with your web application. ... web server don't have to be very aware of each other. ... >> lost in the process and the security of transactions eroded. ...
    (Firewall-Wizards)
  • Re: Web Server not allowing external visitors
    ... | use NATD function of firewall. ... I did all this and lost all access to the internet from the other LAN ... As the Web Server at the moment then is on my FreeBSD machine I do not need ...
    (freebsd-questions)
  • Re: Web server behind Symantec Enterprise Firewall
    ... I've published a virtual IP at the Firewall to which i route the http ... NAT rule AccesoServer was chosen, but client transparency is ... Since the web server is on the LAN, you shouldn't have to add any route ...
    (comp.security.firewalls)