Web DAV vulnerability

anonymous_at_discussions.microsoft.com
Date: 11/06/03


Date: Wed, 5 Nov 2003 16:52:38 -0800

BTW,

This machine is running Win 2k SP4 so it shouldn't be
vulnerable and it is set to DL and install patches every
Friday night so it is current as of Friday.

>-----Original Message-----
>I am getting scanned to death today on the web dav
>vulnerability discussed in MS03-007 security bulletin. I
>installed the IIS lockdown tool and URLScan and they are
>denying the connections but I am seeing scans at least
>every minute. Is there all of a sudden a new outbreak of
>this? Why today are all of these scans showing up in my
>logs?
>
>GET /iisstart.asp - 401
>GET /<Rejected-By-UrlScan> ~/ 404 -
>
>Are you guys seeing this as well?
>
>Thanks,
>Don
>.
>



Relevant Pages

  • user profiles on a dc
    ... we discovered lately created profiles of a few normal users on our DC (w2k ... sp4, patched upto june)! ... is there some vulnerability we have overseen? ...
    (microsoft.public.win2000.security)
  • apply update if OS is not affected but software on it is?
    ... If for example windows 2000 sp4 is not affected from a ... vulnerability, but internet explorer 6 sp1 is affected, ...
    (microsoft.public.security)

Quantcast