Script running against IIS


hi all,

  i've got iis box appears have exploit script running against everyday.  when @ iis logs there multiple entries similar one:

   2013-05-29 12:14:35 w3svc1 servername 192.168.10.31 /edit_image.php dn=1&userfile=/etc/passwd&userfile_name%20....   80 - 192.168.10.31 http/1.0 - - - - 404 0 2 5462 86 31

  there asp.net application logs show unhandled exception has occurred @ same time (event id 1309, event code 3005 request utl trace.axd user host address: 192.168.10.31)

  404 messages, script appears coming iis server (based on ip's).  how can determine if script being ran locally on box or remotely?  

 any appreciated,

 bill

iis logs show ip of requesting machine (user machine or proxy), unless machine running kind of proxy, guess 'script' running local machine.

please note in circumstances, might webapplication running on iis these requests. might due configuration or programming error.

the fact seems nic's ip instead of localhost (127.0.01) suggests code uses hardcoded ip or hostname.


mcp/mcsa/mcts/mcitp



Windows Server  >  Security



Comments

Popular posts from this blog

Motherboard replacement

Remote Desktop App - Error 0x207 or 0x607

Cannot create Full Text Search catalog after upgrading to V12 - Database is not fully started up or it is not in an ONLINE state