Re: anybody seeing this in their logs?

From: Jonathan Maltz [MS-MVP] (jmaltz_at_mvps.org)
Date: 11/04/03


Date: Mon, 3 Nov 2003 22:58:51 -0500

Prevent them? Not possible. Those are OTHER people with Code Red/Nimda
trying to attack your server. As long as you are up to date on security
patches and have a good firewall, I wouldn't worry

-- 
--Jonathan Maltz [Microsoft MVP - Windows Server]
http://www.imbored.biz - A Windows Server 2003 visual, step-by-step
tutorial site :-)
Only reply by newsgroup.  If I see an email I didn't ask for, it will be
deleted without reading.
<anonymous@discussions.microsoft.com> wrote in message
news:000401c3a280$cb28ace0$a001280a@phx.gbl...
What does this mean?
/scripts/root.exe /c+dir
/MSADC/root.exe /c+dir 403
/c/winnt/system32/cmd.exe /c+dir 404
/d/winnt/system32/cmd.exe /c+dir 404
/scripts/..%5c../winnt/system32/cmd.exe /c+dir 500 -
/_vti_bin/..%5c../..%5c../..%
5c../winnt/system32/cmd.exe /c+dir 500 -
/_mem_bin/..%5c../..%5c../..%
5c../winnt/system32/cmd.exe /c+dir 404 -
/msadc/..%5c../..%5c../..%
5c/..Á_../..Á_../..Á_../winnt/system32/cmd.exe /c+dir
403 -
/scripts/..Á_../winnt/system32/cmd.exe /c+dir 500 -
/scripts/winnt/system32/cmd.exe /c+dir 404 -
winnt/system32/cmd.exe /c+dir 404 -
/winnt/system32/cmd.exe /c+dir 404 -
/scripts/..%5c../winnt/system32/cmd.exe /c+dir 500 -
/scripts/..%5c../winnt/system32/cmd.exe /c+dir 500 -
/scripts/..%5c../winnt/system32/cmd.exe /c+dir 500 -
/scripts/..%2f../winnt/system32/cmd.exe /c+dir 500 -
All are GET requests to my Small Business Server 2000
running Exchange and OWA. What can I do to prevent these?
I tried them from home and I get an invalid query string
or some such message. The IP's are coming from MN, MA,
and TX. I am running and IDS so I have all the info if
needed. The system is patched religiously and is as
recent as any security holes Friday evening.
Thanks for the help,
Don


Relevant Pages

  • Re: Recycler security issues on IIS server
    ... > latest upates to the server. ... > like to see the server put behind our firewall, ... other software, install all patches, IISlockdown, URLscan, use the correct ... the procedures you follow may vary depending on your security needs. ...
    (microsoft.public.inetserver.iis.security)
  • Re: #Include with parent paths
    ... >> 80 open to the world, the server was compromised by Nimda. ... Install all necessary service packs/security patches. ... >> 1) Why does enabling parent paths through IIS pose a security risk? ... >> Do all security updates show up through Windows Update? ...
    (microsoft.public.inetserver.iis.security)
  • Re: The clock is running down on OS X "security"
    ... lets see how many security "experts" on this forum will continue ... Windows file sharing on an Internet server? ... So, Michelle, where do you work as a sysadmin? ... I agree with you that any sysadmin that is worth a flip should be keeping up with current patches, ...
    (comp.sys.mac.advocacy)
  • Re: IIS Hack : Anyone explain cause...
    ... I have some counterpoint to your assessment of security. ... Microsoft tries and mostly succeeds to release patches PRIOR to ... > exploitation. ... > server maintenance a challenge, but people have certainly been able to run ...
    (microsoft.public.inetserver.iis)
  • RE: Windows patch mgmt.
    ... from a MS SUS server, then test the patches by ... > of an Ethical Hacker to better assess the security of your ... Attend a course taught by an expert instructor with years of in-the-field ...
    (Security-Basics)

Quantcast