Re: Strange web log

  • From: "Jim Harrison" <jim@xxxxxxxxxxxx>
  • To: "[ISAserver.org Discussion List]" <isalist@xxxxxxxxxxxxx>
  • Date: Mon, 7 Jul 2003 08:15:51 -0700

URLScan would have stopped that one cold.
Be glad IIS stopped it; it's trying to copy cmd.exe into your scripts folder
as script.exe.

 Jim Harrison
 MCP(NT4, W2K), A+, Network+, PCG
 http://www.microsoft.com/isaserver
 http://isaserver.org/Jim_Harrison
 http://isatools.org

 Read the help, books and articles!
----- Original Message ----- 
From: "Mark Strangways" <strangconst@xxxxxxxxxx>
To: "[ISAserver.org Discussion List]" <isalist@xxxxxxxxxxxxx>
Sent: Monday, July 07, 2003 07:43
Subject: [isalist] Strange web log


http://www.ISAserver.org


NachrichtHere is a somewhat weird log from my web logs..
What gets me is the www.google.com after my computer name

Any explanations out there ?

65.50.154.246 anonymous - N 2003-07-07 05:53:04 W3ReverseProxy CR233397-A -
www.google.com 65.50.154.37 81 20 172 225 http TCP GET
http://CR233397-A:81/scripts/..%255c..%255cwinnt/system32/cmd.exe?/c+copy+c:\winnt\system32\cmd.exe+c:\inetpub\scripts\script.exe
text/html Inet 500 0x40000001 Strangconst -

It made it past the firewall of course, but looks like it was blocked by a
inetpub !

Mark S
  ----- Original Message ----- 
  From: William Robertson
  To: [ISAserver.org Discussion List]
  Sent: Monday, July 07, 2003 8:56 AM
  Subject: [isalist] RE: Error 64 - Host not available


  http://www.ISAserver.org


  Hey Mark,



  That's just the thing, as far as all other normal connectivity issues are
concerned, everything pans out 100%.



  -          Name Lookups are fine (63.236.18.30)

  -          tracert dies at  63.146.100.43 (which I presume is their
firewall)

  -          Problem occurs on ANY workstation on my network

  -          Cannot contact the website as they don't respond to e-mails L

  -          No HTTPS

  -          I don't have an external IP Network, but most everyone on the
forum has verified that the site is fine, although I understand that it
would be great to be able to test with ISA "out of the picture" to try and
identify the problem. But it doesn't make any sense at all as the website
(www.earthweb.com) is a "run of the mill", standard HTTP website with no
extra security or anything. So if I can surf every other website in the
world (well, I haven't tried them all but you catch my drift), why can't I
surf this one..



  Cheers

  William R.

  -----Original Message-----
  From: Mark Hippenstiel [mailto:M.Hippenstiel@xxxxxxxxxxxx]
  Sent: 07 July 2003 14:00 PM
  To: [ISAserver.org Discussion List]
  Subject: [isalist] RE: Error 64 - Host not available



  http://www.ISAserver.org

  Hi William,

  just to check the more obvious things: nslookup produces the right IP and
works fine as I suppose. Second, the problem occurs regardless which browser
you're using? Does this apply to any computer in the network or only a
single one? What results does a tracert yield? An idea might be to check
with the website if they have changed anything regarding to communications.
Perhaps it's one of those  MTU issues, is https involved? Are you able to
test the site from your external ip network if you have one?



  Mark





---------------------------------------------------------------------
Everything in this e-mail and attachments relating to the official
business of Columbus Stainless is proprietary to the company. It is
confidential, legally privileged and protected by law. Columbus
Stainless does not own and endorse any other content. Views and
opinions are those of the sender unless clearly stated as being that
of Columbus Stainless. The person addressed in the e-mail is the sole
authorised recipient.  Please notify the sender immediately if it has
unintentionally reached you and do not read, disclose or use the
content in any way. Whilst all reasonable steps are taken to ensure
the accuracy and integrity of information and data transmitted
electronically and to preserve the confidentiality thereof, no
liability or responsibility whatsoever is accepted if information or
data is,for whatever reason, corrupted or does not reach its intended
destination.
---------------------------------------------------------------------

  ------------------------------------------------------
  List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist
  ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp
  ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ
  ------------------------------------------------------
  Other Internet Software Marketing Sites:
  Leading Network Software Directory: http://www.serverfiles.com
  No.1 Exchange Server Resource Site: http://www.msexchange.org
  Windows Security Resource Site: http://www.windowsecurity.com/
  Network Security Library: http://www.secinf.net/
  Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com
  ------------------------------------------------------
  You are currently subscribed to this ISAserver.org Discussion List as:
strangconst@xxxxxxxxxx
  To unsubscribe send a blank email to $subst('Email.Unsub')

------------------------------------------------------
List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist
ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp
ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ
------------------------------------------------------
Other Internet Software Marketing Sites:
Leading Network Software Directory: http://www.serverfiles.com
No.1 Exchange Server Resource Site: http://www.msexchange.org
Windows Security Resource Site: http://www.windowsecurity.com/
Network Security Library: http://www.secinf.net/
Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com
------------------------------------------------------
You are currently subscribed to this ISAserver.org Discussion List as:
jim@xxxxxxxxxxxx
To unsubscribe send a blank email to $subst('Email.Unsub')



Other related posts: