Security Basics mailing list archives

Re: IIS 6 exploited


From: "Ali, Saqib" <docbook.xml () gmail com>
Date: Tue, 11 Aug 2009 09:38:02 -0700

yes it is very possible. probably some vulnerability left unpatched.
also check to see if the hacker installed any type of listener on the
machine e.g. netcat etc. better yet re-install the OS and the web
application stack from scratch to be on the safe side.

saqib
http://kawphi.blogspot.com

On Tue, Aug 11, 2009 at 8:50 AM, asai ajith<asaiajithin () yahoo co in> wrote:

Hi,

One of our web server IIS 6 has been exploited, C:/inetpub/www/cats.txt was modified.

I would like to know how this is possible and what are corrective measures, thanks.

Regards,
Asai



     Yahoo! recommends that you upgrade to the new and safer Internet Explorer 8. 
http://downloads.yahoo.com/in/internetexplorer/

------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, 
how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, 
purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for 
set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital 
certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------



------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how 
it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, 
install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are 
highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------


Current thread: