Security Incidents mailing list archives

Dummies got a sample page


From: James Edwards <jedwards () mail sdsu edu>
Date: Wed, 30 May 2001 10:40:45 -0700

Today I discovered that the sample pages installed when IIS is installed had been defaced (Ya' know the standard "F*** USA Government"). Hadn't noticed earlier since the real pages for the web site were untouched. I noticed that the firewall installed on the NT 4.0 SP6a server wasn't responding, and so I checked "Services". They had *all* been set to "Disabled", so naturally the firewall services weren't running. The system has (and had) all of the current services packs and security patches installed. The site is running Cold Fusion. Any suggestions as to what flavor of attack was employed, and the best methods of countering it would be appreciated.


TIA
--
===================
Jim
mailto:jedwards () mail sdsu edu

_____________________
The most likely way for the world to be destroyed, most experts agree,
is by accident. That's where we come in; we're computer professionals.
We cause accidents.

-- Nathaniel Borenstein


Current thread: