Groups | Blog | Home
all groups > iis security > august 2004 >

iis security : How to stop hackers from changing the index.asp file


Jay_Reborn
8/29/2004 4:25:01 PM
There has been a sudden increase from hackers changing the the root files on
the webserver...

They are exploiting something... but can someone help here???

the message people get is "Fatal Error ownz YOU"
a number of groups on irc.brasnet.org are hitting thousands of websites...
it will soon become a epidemic... unless the security is not addresses...

so i am stating this thread so people can discuss it... can anybody help
here... as I know poieple who have already been hit by this...
Ken Schaefer
8/30/2004 9:38:17 AM
Hi,

There are currently no known IIS exploits that are unpatched

a) ensure that your server is up to date with patches. Use Microsoft
Baseline security Analyser (MBSA) to test your server:
http://www.microsoft.com/technet/security/tools/mbsahome.mspx

b) ensure that your server does not have any weak passwords (it is possible
that someone guessed a password, or is using an account that has no
password)

c) ensure that your box hasn't already been compromised - perhaps your box
was compromised before, and the attackers have installed a backdoor that
lets them get in whenever they want to. Using tools like netstat.exe (comes
with Windows) and TCPView (www.sysinternals.com) can help you look out for
suspicious listening ports.

d) If your machine is currently having pages changed, then it seems that
attackers already have access to the box. Consider calling Microsoft PSS
(Product Support Services) Security Response team in your local area to have
them determine what you should be doing.

Cheers
Ken


[quoted text, click to view]

jeff.nospam NO[at]SPAM zina.com
8/30/2004 2:23:40 PM
On Sun, 29 Aug 2004 16:25:01 -0700, "Jay_Reborn"
[quoted text, click to view]

There may need to be a sudden increase in the skill level or knowledge
of the webmaster... :)

[quoted text, click to view]

Not without a lot more detail.

[quoted text, click to view]

So address it. It's an administrator issue, not a security issue.

[quoted text, click to view]

First, get that system unplugged from the internet. Now. Next,
flatten it. Reformat and reinstall from scratch, applying all the
service packs and hardening the box before you reconnect it to the
internet. Then stop using the server for browsing the internet,
answering email, hitting the IRC channels or any other *client*
application.

See the Microsoft site for security checklists. And next time you
have a problem, post details that would help. Like the operating
system you use for example. Event logs, IIS log entries, security
audit logs, firewall logs and so on.

Miha Pihler
8/30/2004 4:32:23 PM
One thing that you can do is burn a content of webpage to a CD and run it
from there. I would like to see the hacker that changes that index.asp (or
any other) file :-)

Mike

[quoted text, click to view]

Jerry Pisk
8/30/2004 6:22:23 PM
It's not that difficult to change the metabase to point to a different file.
If you gain enough access to break a proper ACL on the files then you have
enough to change the site to point to a different location. Running it off
of a cd will not help you.

Jerry

[quoted text, click to view]

AddThis Social Bookmark Button