Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: IIS and leech

From: Ken Schaefer <ken(at)adOpenStatic.com>
Date: Sun Nov 10 2002 - 19:45:04 EST

  1. Why do you have automatic updates enabled on a production server box? That sounds like trouble waiting to happen.
  2. Many Windows services utilise "dynamic" high order ports. The Port Mapper service on 135 tells remote users what high order port the particular service is using (eg if my app wanted to connect to your messenger service, then it would find out from your port mapper service on 135 which high order port your messenger service had been given).

From: "randall perry" <randallp@domain-logic.com> Subject: IIS and leech

: An IIS box I manage freaked out yesterday. I initially thought that it


: If that wouldn't have happened, I probably would not have found the
following:
: hum.exe which is really leech ftp server was installed on the box and
setup as service to start with the box. I found more than 30 gig of files (movies, MP3s) were there under
: d:\i386\winnt[some characters]\system32\system32\ and some funny directory
names. The movies were broken into 14meg chunks, but had sample avi files in the directory that showed a short clip of what the movie was.
:
: I have no idea how this got planted there by who.
the box)


Lots of ways to get into a box. Ever heard of "Code Red" and "Nimda"? (just for example). Both give the remote user command line access. Depending on what user context you are running the WWW access under, a remote attacker could possibly share a folder and copy some files to the server. Drop a setup script into a "startup" folder, and viola.

Cheers
Ken



This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com Received on Mon Nov 11 20:54:21 2002

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:50 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library