|
|||||||||||
|
RE: Web server crashed, now is trying to contact an IP by port 80 every morning.
From: Dan Harpold <danharp(at)SeaburyTech.com>
Date: Mon Feb 24 2003 - 20:19:38 EST
-----Original Message-----
Well, a "whois 64.0.96.14" shows:
NetRange: 64.0.0.0 - 64.3.255.255
NetName: XOXO-BLK-14 NetHandle: NET-64-0-0-0-1 Parent: NET-64-0-0-0-0 NetType: Direct Allocation NameServer: NAMESERVER1.CONCENTRIC.NET NameServer: NAMESERVER2.CONCENTRIC.NET NameServer: NAMESERVER3.CONCENTRIC.NET NameServer: NAMESERVER.CONCENTRIC.NET If I'm not mistaken, the Automagic Windows Update thing tries to check for updates every day. Concentric hosts some of the Microsoft updates, IIRC. Google shows that Concentric does host some Microsoft stuff, so I think memory is serving me today :). Try disabling the automagic update and see if that is the source of the traffic. Good luck! Steven
"exitus acta probat"
-----Original Message-----
My web server crashed the other day. Got a blue screen and on reboot NTLDR was missing. I reinstalled and reformatted the drive. Simple W2K Server with IIS 5 and current service packs. It sits in a DMZ. Now, each morning (only 2 days so far) at 12:00:45 AM, the machine is trying to contact an outside server via HTTP. The external request, which is being blocked by my firewall, is trying to go to 64.0.96.14. It logs about fifteen attempts over the next ten seconds, then doesn't appear until the next morning. Any thoughts? Dan
<Pre>Lose another weekend managing your IDS?
Take back your personal time.
<Pre>Lose another weekend managing your IDS?
Take back your personal time.
This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:59 EDT |
||||||||||
|
|||||||||||