Re: W2K IIS under attack

From: Miha Pihler (miha.pihler_at_Atlantis-N0Spam.si)
Date: 08/02/03


Date: Sat, 2 Aug 2003 12:54:30 +0200


Is this Internet Web server or is it Intranet. If it is Internet is it
firewall protected? Which ports are opened? It should be only port 80 (and
443 if you use SSL).
Do you have any IIS logs to check out what kind of requests IIS received...

-- 
Mike
MCSA 2K, MCSE 2K, MCT, ...
"Sam" <samwang68@hotmail.com> wrote in message
news:6f9701c358b6$729119f0$a001280a@phx.gbl...
> Please help.
>
> Recently, my Windows 2000 Server is under attack. The
> network is suddently under heavy traffic; the hub LED is
> contantly on. Try to use Systinternals's tool TDImon and
> could not find any special activity.
>
> However, after the traffic LED stops, the IIS is NOT
> working anymore. Try to access the local IIS will get DNS
> error: showing the dnserror.htm. Also, lost the connection
> to other workgroup computers: can not broswer this
> computer form other computers under the local network.
>
> After restart the IIS web service, the website comes back.
>
> Try the VirusScan 7.0 and could not find any virus on the
> computer and apply very latest patches from Microsoft.
>
> Any ideas, experts?
>
> Thank you very much in advance.


Relevant Pages

  • Re: IIS / Web Services Security threats
    ... > believe the weblogic designated ports are open in firewall. ... > Sec configuration may make the network little secure. ... >>> My security team thinks allowing communication between the two IIS ...
    (microsoft.public.dotnet.framework.webservices)
  • Re: Very good break in
    ... IIS is not running on this machine. ... netBIOS ports are blocked at the edge. ... of course there are no iis logs. ... just installing patches is not enough to secure a computer... ...
    (microsoft.public.win2000.security)
  • Re: Installing IIS
    ... You state "but new computers DO COME WITH IT on a separate restore ... This is a simple matter to do with IIS. ... much different from simply installing the software. ... restore drive or in a designated folder on the main drive OR FOR A SMALL ...
    (microsoft.public.sqlserver.setup)
  • Re: Finally, a secure computer
    ... paranoia in the security aspects of IIS administration. ... security at the IBM website is compromised, ... I ran a port check on 10,000 plus ports (I ... > trouble downloading updates [I'm not sure about AVG pro, ...
    (microsoft.public.inetserver.iis.security)
  • Re: Windows 2003 remote admin access
    ... access done in context of the authenticated browsing account (i.e. ... be limited to areas defined as vdirs in IIS and/or FTP. ... particular ports inbound so access on any other ports shouldn't be ... The user does have HTTP and FTP web authoring access but this ...
    (microsoft.public.security)