|
|
|
| |||||||||
![]() |
|
|
«
Previous Thread
|
Next Thread
»
|
Thread Tools | Search this Thread | Rate Thread | Display Modes |
|
|
|
Stop making mediocre tutorials.The best tutorials are video! Camtasia Studio makes it easy to create engaging, buzz-building screen videos at any size, in any popular format. Download the free trial!
|
|
#1
|
|||
|
|||
|
Was I attacked!?! Please Help!!
I can't open IIS Admin console, I get:
Snap-in failed to initialize. Name: - not available - CLSID {etc} I've got a coule of sites running on this server right now, and this morning everything is down. I can't find any services in the Services snap-in that relate to IIS (like my XP machine has IIS Admin service listed there, my Win2k server has nothing). I can't figure out what happend, there was some robot type of attacks in the logs, but nothing seemed like it succeeded (401 and 500 error codes throughout). I'm not sure what I'm missing, please help!! |
|
#2
|
|||
|
|||
|
I'd start with a complete virus scan on the server.
Win2K server should have the same services as you XP Pro box.
__________________
====== Doug G ====== "Hide, hide witch! The good folk come to burn thee. Their keen enjoyment hid behind their gothic mask of duty." -Mark Clifton |
|
#3
|
|||
|
|||
|
Thanks for the reply -
I reinstalled IIS and everything is back to normal. I've got everything back up now, but I'm at a complete loss as to what happend. I've got nothing out of the ordinary in the logs (event viewer, W3SVC logs etc...). I ran a full virus scan (I run Symantec Client Security), and nothing was found. Def's are up to date. I need to figure something to report to the higher ups, they are looking at me right now like I'm crazy lol The only explanation I have is that the server was attacked, but I have no way of proving it, aside from a gut feeling . . . Quote:
|
|
#4
|
|||
|
|||
|
Take a look in your windows event logs, perhaps there is some clue there.
|
|
#5
|
|||
|
|||
|
If I was you I would not go to the "higher ups" and say that it was attacked unless you know for sure it was, and you have a solution on how to prevent it in the future. The most obvious thing that would come to mind is that your registry or files reguarding IIS got corrupted which is not that uncommon actualy.
|
|
#6
|
|||
|
|||
|
I'm familiar with what you mean, but its very strange that the IISAdmin service was also "uninstalled". There was no software of any kind installed on that night, and there are a ton of strange queries in the logs on the day that it crashed . . .
Quote:
|
|
#7
|
|||
|
|||
|
no one here can tell you if you where attacked since we cant see your logs from the server or firewall. I have seen apps disapear from add/remove programs but the files are still on the machine and it still runs though some PCs issues can not be explained. I would however, keep digging to see if you did get attacked and fix the issues or even get a security consultant to come out for a day and look it over.
|
![]() |
| Viewing: Dev Shed Forums > System Administration > IIS > Was I attacked!?! Please Help!! |
| Thread Tools | Search this Thread |
| Display Modes | Rate This Thread |
|
|
|
|