07. august 2001 - 17:07Der er
11 kommentarer og 1 løsning
Analog webstat og iis logfil
Jeg kører IIS5 på en adv. server.. og har lagt mærke til at der bliver forespurgt på nedenstående fil som IKKE findes... Hvad er det for en fil ?? umiddelbart ser det ud som om at der forsøges at komme ind???
ved forsøg på at åbne filen får jeg følgende resultat: The IDQ file default.ida could not be found.
Og ved søgning på .ida har jeg fundet dette: Fast-Spreading Worm Exploits Microsoft IIS Flaw
A new worm that targets vulnerability in Microsoft\'s Internet Information Services (IIS) Web server software appears to be spreading quickly, say experts at eEye Digital Security.
The firm, based here, says it spotted the worm after analyzing packet logs and information it received Friday from two network administrators whose systems were attacked.
\"This thing is big. A lot of systems are being infected,\" says Marc Maiffret, chief hacking officer at eEye Digital Security. \"We\'ve already heard numbers of at least in the 5,000 range over a three-day period, and that was two days ago.\"
Dubbed .ida \"Code Red,\" the worm exploits a vulnerability in the indexing services within IIS that makes it susceptible to buffer overflow attacks. Engineers at eEye Digital Security issued a warning about the vulnerability on June 18.
Systems running Windows NT 4.0 with IIS 4.0 or IIS 5.0 enabled, Windows 2000 Professional, Server, Advanced Server and Datacenter Server, and beta versions of Windows XP are affected.
After infecting an IIS Web server, the worm generates a list of 100 random IP addresses to scan for new IIS servers to infect, Maiffret says. It also defaces Web pages with the message \"Hacked by Chinese!\" he says.
Because the worm uses the same seed for \"randomization\" of IP addresses, each new infected host will start scanning at the same IP address, resulting in hosts that are at the beginning of the list getting bombarded, he says. That creates the potential for denial-of-service attacks against those hosts, he says.
\"This is a pretty good wake-up call for people to realize they need to stay up-to-date on patches,\" Maiffret says.
Microsoft last month issued patches for Windows NT 4.0, as well as Windows 2000 Professional, Server and Advanced Server and advised users of Windows 2000 Datacenter Server software to contact their OEM because those patches are hardware-specific.
Et typisk tegn på at du er inficeret er at din server viser en side hvor der står \'Hacked by Chineese\' og så en url til en eller anden side, mener det er worm.com
Ved det ikke, men det vel en krypteret måde for virusen at smadre din server på ??
Synes godt om
Ny brugerNybegynder
Din løsning...
Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.