Welcome to HostingForumz.com!
FAQFAQ      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

IIS 5.0 log file contents question...

 
   Web Hosting Problem Solving Community! (Home) -> IIS RSS
Next:  Enable Network File System Support  
Author Message
none22

External


Since: Oct 01, 2003
Posts: 1



(Msg. 1) Posted: Wed Oct 01, 2003 3:01 pm
Post subject: IIS 5.0 log file contents question...
Archived from groups: microsoft>public>inetserver>iis (more info?)

I have a hosted web site that is running under IIS 5.0 on
a remote server. I have access to the logs for my site
(s). I have been reviewing the log files and see a
unusual set of entries that I can not fine any information
on. Any help determining what is going on is
appreciated...

This usually appears as a set of three commands as follows:
- a GET for a page as in GET /{page name}
- a SEARCH as in SEARCH /
- a SEARCH as in SEARCH /{bunch of stuff}

The {bunch of stuff} is:
- 269 'A's followed by
- 8 sets of '??{single unprintable character}' followed by
- 33 '?' followed by
- 260 lower case letters followed by
- 3421 'N'

Can anyone tell me what is going on here? What this stuff
might be? I will see this suff in the logs multiple times
a day and at some points multiple times a minute!

I have looked in some IIS books and they indicate that the
SEARCH command is for a news server. I am not running
one. Thoughts? Ideas? Information?

Thanks.

 >> Stay informed about: IIS 5.0 log file contents question... 
Back to top
Login to vote
doug1

External


Since: Aug 26, 2003
Posts: 43



(Msg. 2) Posted: Wed Oct 01, 2003 3:18 pm
Post subject: IIS 5.0 log file contents question... [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

post the "actual" log file entries so we can take a
look...

(initially, it looks like some sort of attack from the
internet. what we want to see is if the attack was
successful or not.)

doug
 >-----Original Message-----
 >I have a hosted web site that is running under IIS 5.0
on
 >a remote server. I have access to the logs for my site
 >(s). I have been reviewing the log files and see a
 >unusual set of entries that I can not fine any
information
 >on. Any help determining what is going on is
 >appreciated...
 >
 >This usually appears as a set of three commands as
follows:
 >- a GET for a page as in GET /{page name}
 >- a SEARCH as in SEARCH /
 >- a SEARCH as in SEARCH /{bunch of stuff}
 >
 >The {bunch of stuff} is:
 >- 269 'A's followed by
 >- 8 sets of '??{single unprintable character}' followed
by
 >- 33 '?' followed by
 >- 260 lower case letters followed by
 >- 3421 'N'
 >
 >Can anyone tell me what is going on here? What this
stuff
 >might be? I will see this suff in the logs multiple
times
 >a day and at some points multiple times a minute!
 >
 >I have looked in some IIS books and they indicate that
the
 >SEARCH command is for a news server. I am not running
 >one. Thoughts? Ideas? Information?
 >
 >Thanks.
 >.
 ><!-- ~MESSAGE_AFTER~ -->

 >> Stay informed about: IIS 5.0 log file contents question... 
Back to top
Login to vote
user658

External


Since: Aug 26, 2003
Posts: 1525



(Msg. 3) Posted: Fri Oct 03, 2003 3:59 pm
Post subject: Re: IIS 5.0 log file contents question... [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

On Wed, 1 Oct 2003 12:01:33 -0700, "onlyabill" <none DeleteThis @hotmail.com>
wrote:

 >I have a hosted web site that is running under IIS 5.0 on
 >a remote server. I have access to the logs for my site
 >(s). I have been reviewing the log files and see a
 >unusual set of entries that I can not fine any information
 >on. Any help determining what is going on is
 >appreciated...
 >
 >This usually appears as a set of three commands as follows:
 >- a GET for a page as in GET /{page name}
 >- a SEARCH as in SEARCH /
 >- a SEARCH as in SEARCH /{bunch of stuff}
 >
 >The {bunch of stuff} is:
 >- 269 'A's followed by
 >- 8 sets of '??{single unprintable character}' followed by
 >- 33 '?' followed by
 >- 260 lower case letters followed by
 >- 3421 'N'
 >
 >Can anyone tell me what is going on here? What this stuff
 >might be? I will see this suff in the logs multiple times
 >a day and at some points multiple times a minute!
 >
 >I have looked in some IIS books and they indicate that the
 >SEARCH command is for a news server. I am not running
 >one. Thoughts? Ideas? Information?

Nimda and varients, as well as scripted attacks. Make sure your
server is patched and hardened, use URLScan to deny the requests.

<a style='text-decoration: underline;' href="http://www.microsoft.com/security/" target="_blank">http://www.microsoft.com/security/</a>
<a style='text-decoration: underline;' href="http://securityadmin.info/" target="_blank">http://securityadmin.info/</a>

Jeff<!-- ~MESSAGE_AFTER~ -->
 >> Stay informed about: IIS 5.0 log file contents question... 
Back to top
Login to vote
Display posts from previous:   
Related Topics:
Display file contents for all extensions - I have a server with a directory that needs to have IIS serve several files all with varying file extensions. Basically, we need the .* extensions\ to be able to be requested and served, rather than giving a 404 error. Any ideas on how to do this if we...

IIS / DFS contents - Hi I am using a few web server which are getting there content in a DFS share. I often have hangs (IIS degug diag only show a Com + sta pile up). When the system hangs, i get the process system (PID 4) going up in the task manager and a perfmon show m...

Log file question... - Is there a preferred application for analyzing the SMTP log files? Also, I have had complaints from people that they have not received my emails. Is there an easy way to open the log files and see if any servers are rejecting my IP. I have heard that..

IIS ftp file question - IIS 5.0 FTP server , W2k server>> I ftp large files into this thing from a client on the network. If the client crashes, the file stays around on the server for some time and then disappears. I want it to stay for good (even though it's not the c...

Contents are encrypted - When I create a new Web application in Visual Studio, the contents are being encrypted. I can't rename or delete folders, although I appear to have full control both as a user and an administrator. I installed PGP recently. Would this cause these..
   Web Hosting Problem Solving Community! (Home) -> IIS All times are: Pacific Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



[ Contact us | Terms of Service/Privacy Policy ]