Security Incidents mailing list archives

Web server crashed, now is trying to contact an IP by port 80 every morning.


From: "Dan Harpold" <danharp () SeaburyTech com>
Date: Sun, 23 Feb 2003 21:20:01 -0600

My web server crashed the other day. Got a blue screen and on reboot
NTLDR was missing. I reinstalled and reformatted the drive. Simple W2K
Server with IIS 5 and current service packs. It sits in a DMZ.

Now, each morning (only 2 days so far) at 12:00:45 AM, the machine is
trying to contact an outside server via HTTP. The external request,
which is being blocked by my firewall, is trying to go to 64.0.96.14. It
logs about fifteen attempts over the next ten seconds, then doesn't
appear until the next morning.

Any thoughts?

Dan 


----------------------------------------------------------------------------

<Pre>Lose another weekend managing your IDS?
Take back your personal time.
15-day free trial of StillSecure Border Guard.</Pre>
<A href="http://www.securityfocus.com/stillsecure";> http://www.securityfocus.com/stillsecure </A>



Current thread: