Hi,
Does anyone know what kind of attack is this and how can be prevented?
IIS servers will not be able to serve any other pages for the time when this attack is active.
We use UrlScan and we have IIS 5/6 patched with latest security patches.
However from IIS logs I can not see much about how this attack is performed.
Thank you,
Chris
x.x.x.x is our server IP address.
2003-12-21 17:21:53 211.38.90.129 - x.x.x.x 80 HEAD /index.asp - 200 362 40 - - -
2003-12-21 17:21:59 211.38.90.129 - x.x.x.x 80 - - - 404 245 65 - - -
2003-12-21 17:22:07 211.38.90.129 - x.x.x.x 80 - - - 404 143 109 - - -
2003-12-21 17:22:17 211.38.90.129 - x.x.x.x 80 - - - 404 245 103 - - -
2003-12-21 17:22:26 211.38.90.129 - x.x.x.x 80 - - - 404 245 115 - - -
2003-12-21 17:22:36 211.38.90.129 - x.x.x.x 80 - - - 404 245 103 - - -
2003-12-21 17:22:47 211.38.90.129 - x.x.x.x 80 - - - 404 245 104 - - -
2003-12-21 17:22:59 211.38.90.129 - x.x.x.x 80 - - - 404 245 98 - - -
2003-12-21 17:23:10 211.38.90.129 - x.x.x.x 80 - - - 404 245 110 - - -
2003-12-21 17:23:22 211.38.90.129 - x.x.x.x 80 - - - 404 245 98 - - -
2003-12-21 17:23:34 211.38.90.129 - x.x.x.x 80 - - - 404 245 112 - - -
2003-12-21 17:23:47 211.38.90.129 - x.x.x.x 80 - - - 404 245 130 - - -
2003-12-21 17:24:01 211.38.90.129 - x.x.x.x 80 - - - 404 245 120 - - -
2003-12-21 17:24:13 211.38.90.129 - x.x.x.x 80 - - - 404 245 140 - - -
2003-12-21 17:24:27 211.38.90.129 - x.x.x.x 80 - - - 404 245 120 - - -
2003-12-21 17:24:40 211.38.90.129 - x.x.x.x 80 - - - 404 245 112 - - -
2003-12-21 17:24:53 211.38.90.129 - x.x.x.x 80 - - - 404 245 125 - - -
2003-12-21 17:25:06 211.38.90.129 - x.x.x.x 80 - - - 404 245 115 - - -
2003-12-21 17:25:20 211.38.90.129 - x.x.x.x 80 - - - 404 143 124 - - -
2003-12-21 17:25:33 211.38.90.129 - x.x.x.x 80 - - - 404 245 125 - - -
2003-12-21 17:25:46 211.38.90.129 - x.x.x.x 80 - - - 404 245 125 - - -
2003-12-21 17:26:00 211.38.90.129 - x.x.x.x 80 - - - 404 245 126 - - -
2003-12-21 17:26:13 211.38.90.129 - x.x.x.x 80 - - - 404 245 75 - - -
2003-12-21 17:26:27 211.38.90.129 - x.x.x.x 80 - - - 404 245 123 - - -
2003-12-21 17:26:41 211.38.90.129 - x.x.x.x 80 - - - 404 245 124 - - -
2003-12-21 17:26:55 211.38.90.129 - x.x.x.x 80 - - - 404 245 75 - - -
2003-12-21 17:27:09 211.38.90.129 - x.x.x.x 80 - - - 404 245 125 - - -
2003-12-21 17:27:23 211.38.90.129 - x.x.x.x 80 - - - 404 245 126 - - -
2003-12-21 17:27:36 211.38.90.129 - x.x.x.x 80 - - - 404 245 115 - - -
2003-12-21 17:27:50 211.38.90.129 - x.x.x.x 80 - - - 404 245 107 - - -
2003-12-21 17:28:04 211.38.90.129 - x.x.x.x 80 - - - 404 245 123 - - -
2003-12-21 17:28:18 211.38.90.129 - x.x.x.x 80 - - - 404 245 107 - - -
2003-12-21 17:28:31 211.38.90.129 - x.x.x.x 80 - - - 404 245 115 - - -
2003-12-21 17:28:45 211.38.90.129 - x.x.x.x 80 - - - 404 245 109 - - -
2003-12-21 17:28:58 211.38.90.129 - x.x.x.x 80 - - - 404 245 123 - - -
2003-12-21 17:29:12 211.38.90.129 - x.x.x.x 80 - - - 404 245 121 - - -
2003-12-21 17:29:26 211.38.90.129 - x.x.x.x 80 - - - 404 245 107 - - -
2003-12-21 17:29:40 211.38.90.129 - x.x.x.x 80 - - - 404 245 109 - - -
2003-12-21 17:29:54 211.38.90.129 - x.x.x.x 80 - - - 404 245 140 - - -
2003-12-21 17:30:08 211.38.90.129 - x.x.x.x 80 - - - 404 245 112 - - -
2003-12-21 17:30:21 211.38.90.129 - x.x.x.x 80 - - - 404 245 90 - - -
2003-12-21 17:30:35 211.38.90.129 - x.x.x.x 80 - - - 404 245 112 - - -
2003-12-21 17:30:49 211.38.90.129 - x.x.x.x 80 - - - 404 245 90 - - -
2003-12-21 17:31:03 211.38.90.129 - x.x.x.x 80 - - - 404 245 121 - - -
2003-12-21 17:31:17 211.38.90.129 - x.x.x.x 80 - - - 404 245 93 - - -
2003-12-21 17:31:31 211.38.90.129 - x.x.x.x 80 - - - 404 245 130 - - -
2003-12-21 17:31:44 211.38.90.129 - x.x.x.x 80 - - - 404 245 96 - - -
2003-12-21 17:31:58 211.38.90.129 - x.x.x.x 80 - - - 404 245 139 - - -
2003-12-21 17:32:12 211.38.90.129 - x.x.x.x 80 - - - 404 245 99 - - -
2003-12-21 17:32:25 211.38.90.129 - x.x.x.x 80 - - - 404 245 123 - - -
2003-12-21 17:32:40 211.38.90.129 - x.x.x.x 80 - - - 404 245 124 - - -
2003-12-21 17:32:53 211.38.90.129 - x.x.x.x 80 - - - 404 245 91 - - -
2003-12-21 17:33:07 211.38.90.129 - x.x.x.x 80 - - - 404 245 95 - - -
2003-12-21 17:33:21 211.38.90.129 - x.x.x.x 80 - - - 404 245 93 - - -
2003-12-21 17:33:35 211.38.90.129 - x.x.x.x 80 - - - 404 245 91 - - -
2003-12-21 17:33:49 211.38.90.129 - x.x.x.x 80 - - - 404 245 95 - - -
2003-12-21 17:34:02 211.38.90.129 - x.x.x.x 80 - - - 404 245 109 - - -
2003-12-21 17:34:16 211.38.90.129 - x.x.x.x 80 - - - 404 245 91 - - -
2003-12-21 17:34:30 211.38.90.129 - x.x.x.x 80 - - - 404 245 96 - - -
2003-12-21 17:34:44 211.38.90.129 - x.x.x.x 80 - - - 404 245 95 - - -
2003-12-21 17:34:58 211.38.90.129 - x.x.x.x 80 - - - 404 245 91 - - -
2003-12-21 17:35:11 211.38.90.129 - x.x.x.x 80 - - - 404 245 113 - - -
2003-12-21 17:35:25 211.38.90.129 - x.x.x.x 80 - - - 404 245 113 - - -
2003-12-21 17:35:39 211.38.90.129 - x.x.x.x 80 - - - 404 245 113 - - -
2003-12-21 17:35:52 211.38.90.129 - x.x.x.x 80 - - - 404 245 92 - - -
2003-12-21 17:36:06 211.38.90.129 - x.x.x.x 80 - - - 404 245 92 - - -
2003-12-21 17:36:21 211.38.90.129 - x.x.x.x 80 - - - 404 245 92 - - -
2003-12-21 17:36:34 211.38.90.129 - x.x.x.x 80 - - - 404 245 92 - - -
2003-12-21 17:36:48 211.38.90.129 - x.x.x.x 80 - - - 404 245 92 - - -
2003-12-21 17:37:02 211.38.90.129 - x.x.x.x 80 - - - 404 245 92 - - -
2003-12-21 17:37:16 211.38.90.129 - x.x.x.x 80 - - - 404 245 92 - - -
2003-12-21 17:37:30 211.38.90.129 - x.x.x.x 80 - - - 404 245 92 - - -
2003-12-21 17:37:44 211.38.90.129 - x.x.x.x 80 - - - 404 245 95 - - -
2003-12-21 17:37:57 211.38.90.129 - x.x.x.x 80 - - - 404 245 98 - - -
2003-12-21 17:38:11 211.38.90.129 - x.x.x.x 80 - - - 404 245 101 - - -
2003-12-21 17:38:25 211.38.90.129 - x.x.x.x 80 - - - 404 245 104 - - -
2003-12-21 17:38:38 211.38.90.129 - x.x.x.x 80 - - - 404 245 67 - - -
2003-12-21 17:38:52 211.38.90.129 - x.x.x.x 80 - - - 404 143 148 - - -
2003-12-21 17:39:06 211.38.90.129 - x.x.x.x 80 HEAD /etc/passwd /c+dir+c:\ 404 144 138 - - -
2003-12-21 17:39:20 211.38.90.129 - x.x.x.x 80 - - - 404 245 112 - - -
2003-12-21 17:39:34 211.38.90.129 - x.x.x.x 80 - - - 404 245 116 - - -
2003-12-21 17:39:48 211.38.90.129 - x.x.x.x 80 - - - 404 245 122 - - -
2003-12-21 17:40:01 211.38.90.129 - x.x.x.x 80 - - - 404 245 116 - - -
2003-12-21 17:40:15 211.38.90.129 - x.x.x.x 80 - - - 404 245 122 - - -
2003-12-21 17:40:29 211.38.90.129 - x.x.x.x 80 - - - 404 245 116 - - -
2003-12-21 17:40:43 211.38.90.129 - x.x.x.x 80 - - - 404 245 122 - - -
2003-12-21 17:40:56 211.38.90.129 - x.x.x.x 80 - - - 404 245 116 - - -
2003-12-21 17:41:10 211.38.90.129 - x.x.x.x 80 - - - 404 245 122 - - -
2003-12-21 17:41:24 211.38.90.129 - x.x.x.x 80 - - - 404 245 123 - - -
2003-12-21 17:41:38 211.38.90.129 - x.x.x.x 80 - - - 404 245 123 - - -
2003-12-21 17:41:53 211.38.90.129 - x.x.x.x 80 - - - 404 245 123 - - -