Re: IIS Dynamically Adds IP Adresses in Paket FIltering

From: Bernard Cheah [MVP] (qbernard_at_hotmail.com.discuss)
Date: 09/13/05


Date: Tue, 13 Sep 2005 14:28:30 +0800

You could try ADSI -
http://www.iisfaq.com/Default.aspx?tabid=2804

look for IIsIPSecurity metabase key and few related keys.

-- 
Regards,
Bernard Cheah
http://www.iis-resources.com/
http://www.iiswebcastseries.com/
http://www.msmvps.com/bernard/
"Cnsrvative" <Cnsrvative@discussions.microsoft.com> wrote in message 
news:590F75BB-D2D8-414D-9EB8-CDBBA6931A9D@microsoft.com...
> Have been hunting down this ghost for 2 months now - any feedback is
> appreciated...
>
> We have a Server 2003 Std Box, running IIS 6.0 (all updates installed  - 
> NOT
> 2003 SP1).  It hosts Sharepoint portal server, and our Project server and
> only allows access to clients on our LAN.
>
> In IIS, (Computer Management|Servuices and Applications|Internet Inford
> mation Services|Web SIties|Properties|Directory Security|Ip Address and
> domain name Restrictions|Edit) we have NOT configured any IP addresses or
> domains in this box, and have by default GRANTED ACCESS to all computers.
>
> Occasionally, and at random, this box will become populated with IP
> addresses on our LAN - thus denying them access.  They can be client IP's,
> other member server IP's, even Domain Controller IP's and they appear 
> totally
> at random and are NOT always the same IP addresses.
>
> Have posted this in the SPS newsgroup and no one had ever heard of
> SHarepoint behaving like this.  Wondering if anyone has seen IIS 
> dynamically
> update this information, or if they have seen another program interfere 
> with
> IIS in this way.
>
> Thanks in advance for any insight! 


Relevant Pages

  • [NT] Heap Overrun in HTR Chunked Encoding Could Enable Web Server Compromise
    ... This patch eliminates a newly discovered vulnerability affecting Internet ... in IIS 4.0 and 5.0, and could likewise be used to overrun heap memory on ... allowing code to be run on the server. ... * Microsoft has long recommended disabling HTR functionality unless there ...
    (Securiteam)
  • Re: Problem with connect computer wizard
    ... Make sure the Windows XP client is pointing to the SBS 2003 server as ... Please collect the IIS metabase and the latest IIS log files further ... This newsgroup only focuses on SBS technical issues. ...
    (microsoft.public.windows.server.sbs)
  • RE: IIS Key pairs (how to export an IIS 4.0 self-issued Root CA a nd import into new IIS 4.0 box)
    ... IIS key to an Intel SSL acelerator ... it issues client certificates to the end users. ... Step I - Installing the New Server ... Install NT SP 3 ONLY ...
    (Focus-Microsoft)
  • Re: SBS 2003 After Service Pack 1 for SBS
    ... we can conclude the SBS 2003 SP1 has been applied ... Please help me collect the IIS metabase to check ... and using server management console to reproduce the problem. ... This newsgroup only focuses on SBS technical issues. ...
    (microsoft.public.windows.server.sbs)
  • FW: Microsoft Security Advisory MS 03-007
    ... am trying to find a vulnerability tester/script and I could test it out ... Department of the Army server that had been compromised and that this ... announcement covers IIS 5.1 but not IIS 6, ... How a Hacker Uses SQL Injection to Steal Your SQL Data! ...
    (Focus-Microsoft)