Groups | Blog | Home
all groups > iis security > january 2004 >

iis security : Folder with no NAME



Dumb Founded
1/20/2004 12:21:56 PM
A folder was found on our WEB server running Adv 2000, in
the wwwroot folder. It had no name and had several
hundred subfolders which each had several hunder more
subfolders.
When we tryed to delet or move the folder an access
denied dialog box appeared.
Skorpion (CET)
1/21/2004 4:13:00 AM
On 20 Jan 2004, in news:0dda01c3df93$0cce5060$a101280a@phx.gbl, "Dumb
Founded" <anonymous@discussions.microsoft.com> scrawled:

[quoted text, click to view]

My first guess...

You have been setup as anon warez server. (I suspect you have anonymous FTP
enabled on this machine.)

The folders to which you refer are probably created using special characters
and strings of special characters.

You can search MS for a KB article describing how to delete the folders.

Also, address the anonymous FTP security situation (if that's what it really
is).

--
Skorpion (CET)

-------------------------------------------------------------
People who wear Halloween costumes are sometimes mistaken for
monsters.
-- Bruce Sterling
Karl Levinson [x y] mvp
1/21/2004 6:35:16 AM
Agreed. Look here:

http://securityadmin.info/faq.asp#ftpfolder
http://securityadmin.info/faq.asp#hacked
http://securityadmin.info/faq.asp#harden
http://www.microsoft.com/technet/security

Make sure the anonymous FTP user [e.g. IUSR by default] never has both read
and write permission to any folder.

Disable the IIS FTP service if you're not using it.

Install all Microsoft patches religiously.

Run URLScan free from the above microsoft url on all your IIS web servers.

Use the free hardening checklists for Windows and IIS at the links above.

Make sure you're running a firewall.


[quoted text, click to view]

AddThis Social Bookmark Button