Tool prevents logging of default.ida (IIS / NT)

From: Hardy Krause (krauseat_private)
Date: Fri Aug 24 2001 - 14:59:31 PDT

  • Next message: Snow, Corey: "RE: Cisco Security Advisory: CBOS Web-based Configuration Utility Vulnerability"

    Code Red Worm destroyed most of our log files also after patching the
    server.
    
    We have created a little ISAPI-Filter. It performs a check if someone calls
    the default.ida. In this case the session will be closed immediately and it
    does not take place an entry in the logfile.
    
    Our tool can be installed on servers running IIS4 or IIS5.
    
    It can be downloaded free of charge from http://www.netcomplett.de/software/
    (Look for ncIdaBlocker).
    
    Best regards
    
    Hardy Krause
    
    eMail: infoat_private
    internet: www.netcomplett.de
    tel: +49-345-5636185
    fax: +49-345-5636188
    
    netcomplett
    fiete-schulze-str. 13
    06116 Halle
    



    This archive was generated by hypermail 2b30 : Fri Aug 24 2001 - 15:53:47 PDT