Script running against IIS
hi all,
i've got iis box appears have exploit script running against everyday. when @ iis logs there multiple entries similar one:
2013-05-29 12:14:35 w3svc1 servername 192.168.10.31 /edit_image.php dn=1&userfile=/etc/passwd&userfile_name%20.... 80 - 192.168.10.31 http/1.0 - - - - 404 0 2 5462 86 31
there asp.net application logs show unhandled exception has occurred @ same time (event id 1309, event code 3005 request utl trace.axd user host address: 192.168.10.31)
404 messages, script appears coming iis server (based on ip's). how can determine if script being ran locally on box or remotely?
any appreciated,
bill
iis logs show ip of requesting machine (user machine or proxy), unless machine running kind of proxy, guess 'script' running local machine.
please note in circumstances, might webapplication running on iis these requests. might due configuration or programming error.
the fact seems nic's ip instead of localhost (127.0.01) suggests code uses hardcoded ip or hostname.
mcp/mcsa/mcts/mcitp
Windows Server > Security
Comments
Post a Comment