IIS
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationIIS

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
Stop making mediocre tutorials.The best tutorials are video! Camtasia Studio makes it easy to create engaging, buzz-building screen videos at any size, in any popular format. Download the free trial!
  #1  
Old March 29th, 2005, 08:18 AM
slylos slylos is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Feb 2005
Location: Fort Pierce, FL
Posts: 227 slylos User rank is Private First Class (20 - 50 Reputation Level)slylos User rank is Private First Class (20 - 50 Reputation Level) 
Time spent in forums: 2 Days 4 h 8 m 51 sec
Reputation Power: 4
Was I attacked!?! Please Help!!

I can't open IIS Admin console, I get:
Snap-in failed to initialize. Name: - not available -
CLSID {etc}

I've got a coule of sites running on this server right now, and this morning everything is down. I can't find any services in the Services snap-in that relate to IIS (like my XP machine has IIS Admin service listed there, my Win2k server has nothing). I can't figure out what happend, there was some robot type of attacks in the logs, but nothing seemed like it succeeded (401 and 500 error codes throughout). I'm not sure what I'm missing, please help!!

Reply With Quote
  #2  
Old March 29th, 2005, 09:36 PM
Doug G Doug G is offline
Grumpier Old Moderator
Dev Shed God 12th Plane (10500 - 10999 posts)
 
Join Date: Jun 2003
Posts: 10,679 Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level) 
Time spent in forums: 4 Weeks 1 Day 14 h 50 m 53 sec
Reputation Power: 688
I'd start with a complete virus scan on the server.

Win2K server should have the same services as you XP Pro box.
__________________
======
Doug G
======
"Hide, hide witch! The good folk come to burn thee. Their keen enjoyment hid behind their gothic mask of duty." -Mark Clifton

Reply With Quote
  #3  
Old March 29th, 2005, 10:24 PM
slylos slylos is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Feb 2005
Location: Fort Pierce, FL
Posts: 227 slylos User rank is Private First Class (20 - 50 Reputation Level)slylos User rank is Private First Class (20 - 50 Reputation Level) 
Time spent in forums: 2 Days 4 h 8 m 51 sec
Reputation Power: 4
Thanks for the reply -
I reinstalled IIS and everything is back to normal. I've got everything back up now, but I'm at a complete loss as to what happend. I've got nothing out of the ordinary in the logs (event viewer, W3SVC logs etc...). I ran a full virus scan (I run Symantec Client Security), and nothing was found. Def's are up to date. I need to figure something to report to the higher ups, they are looking at me right now like I'm crazy lol
The only explanation I have is that the server was attacked, but I have no way of proving it, aside from a gut feeling . . .

Quote:
Originally Posted by Doug G
I'd start with a complete virus scan on the server.

Win2K server should have the same services as you XP Pro box.

Reply With Quote
  #4  
Old March 30th, 2005, 07:43 PM
Doug G Doug G is offline
Grumpier Old Moderator
Dev Shed God 12th Plane (10500 - 10999 posts)
 
Join Date: Jun 2003
Posts: 10,679 Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level) 
Time spent in forums: 4 Weeks 1 Day 14 h 50 m 53 sec
Reputation Power: 688
Take a look in your windows event logs, perhaps there is some clue there.

Reply With Quote
  #5  
Old March 31st, 2005, 09:49 AM
juniperr juniperr is offline
network dude
Dev Shed Intermediate (1500 - 1999 posts)
 
Join Date: Dec 2003
Posts: 1,679 juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level) 
Time spent in forums: 1 Week 6 Days 21 h 55 m 2 sec
Reputation Power: 85
If I was you I would not go to the "higher ups" and say that it was attacked unless you know for sure it was, and you have a solution on how to prevent it in the future. The most obvious thing that would come to mind is that your registry or files reguarding IIS got corrupted which is not that uncommon actualy.

Reply With Quote
  #6  
Old March 31st, 2005, 10:28 AM
slylos slylos is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Feb 2005
Location: Fort Pierce, FL
Posts: 227 slylos User rank is Private First Class (20 - 50 Reputation Level)slylos User rank is Private First Class (20 - 50 Reputation Level) 
Time spent in forums: 2 Days 4 h 8 m 51 sec
Reputation Power: 4
I'm familiar with what you mean, but its very strange that the IISAdmin service was also "uninstalled". There was no software of any kind installed on that night, and there are a ton of strange queries in the logs on the day that it crashed . . .

Quote:
Originally Posted by juniperr
If I was you I would not go to the "higher ups" and say that it was attacked unless you know for sure it was, and you have a solution on how to prevent it in the future. The most obvious thing that would come to mind is that your registry or files reguarding IIS got corrupted which is not that uncommon actualy.

Reply With Quote
  #7  
Old March 31st, 2005, 12:23 PM
juniperr juniperr is offline
network dude
Dev Shed Intermediate (1500 - 1999 posts)
 
Join Date: Dec 2003
Posts: 1,679 juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level) 
Time spent in forums: 1 Week 6 Days 21 h 55 m 2 sec
Reputation Power: 85
no one here can tell you if you where attacked since we cant see your logs from the server or firewall. I have seen apps disapear from add/remove programs but the files are still on the machine and it still runs though some PCs issues can not be explained. I would however, keep digging to see if you did get attacked and fix the issues or even get a security consultant to come out for a day and look it over.

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationIIS > Was I attacked!?! Please Help!!


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 3 hosted by Hostway