Psst! Did you know DevelopmentNow is a mobile web site design agency?

Contact us for help mobilizing your site, or to sign up for our beta Mobile Web SDK!
all groups > iis security > november 2005 >

iis security : FTP Server Logging


MikeV06
11/30/2005 11:57:01 AM
I monitor my router and ftp logs on Server 2003. As would be expected, port
21 packets show up in both. However, I have an instance where the router
shows an incoming and outgoing packet for port 21. However, no entry was
made in the ftp log.

The router shows

Nov 29, 2005 12:25:37.302 UTC - 58.12.31.109 : 62649 >>> 192.168.1.95 :
21 - FTP Scan
Nov 29, 2005 12:25:37.302 UTC - 192.168.1.95 : 21 >>> 58.12.31.109 :
62649

The router would not generate an outgoing packet, hence the packet had to
have been generated by the server by the program listening on port 21
(ftp).

Nothing from that ip address is listed in the ftp log, the http log, the
firewall log, or the event log. I did not have a deny access entry in
directory security for that range of addresses (I do now).

Unless I am missing something, this would suggest that a packet was
processed by the ftp server but not recorded in the ftp log. How is that
possible and how to I correct it?

Thanks.

jeff.nospam NO[at]SPAM zina.com
12/6/2005 4:49:18 AM
[quoted text, click to view]

Or it's processed by another program.

MikeV06
12/6/2005 7:34:02 AM
[quoted text, click to view]

I have used netstat -nab and procexp to see what the system is doing and do
not see anything strange. I have not seen the pattern happen again since
the one time.

How could I monitor the port for that activity? I wish I had some of the
AddThis Social Bookmark Button