Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations TouchToneTommy on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Malicious activity in web logs 1

Status
Not open for further replies.

packdragon

IS-IT--Management
Jan 21, 2003
459
US
We hav a web server (behind a firewall) that has tons and tons of web log entries that look like this:

2004-02-18 00:15:37 66.12.130.190 - 172.16.201.65 80 SEARCH /AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAddddrfsmlgrpehggpdidjlfrjikljijljljskgkhjlipkgkjjgloqpidjndjjndfididjlddddddhdigssejlgslsskhfmlosljnddlopjlgpdelidloilsp
...

This actually goes on and on across numerous lines (I only copied a few lines so you get an idea of what I'm seeing). I'm guessing this is someone trying to do a buffer overflow on the web server? Entries like this happen over and over again.

My question is this: Is there some kind of monitoring software for Windows 2000 Server that can look for crap like this and deny access to the offending IP address? Kind of like locking out users who enter a bad password too many times.

- Zoe, that's ZOH-EEE, get it right please
- Just a little ol' MCP at Solien Technology
-
 
Try running network monitor on the web server and capturing some network traffic. You can also enable auditing so that the system keeps a security log......
 
Sounds like someone is trying the old gnoats webserver buffer overrun exploit. Take a look at URLscan. You can configure it sto strip stuff like that out.

 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top