ASP Development
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
 
User Name:
Password:
Remember me
 
Go Back   Dev Articles Community ForumsProgrammingASP Development

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Display Modes
 
Unread Dev Articles Community Forums Sponsor:
  #1  
Old February 22nd, 2004, 12:32 PM
Discusman Discusman is offline
Registered User
Dev Articles Newbie (0 - 499 posts)
 
Join Date: Feb 2004
Posts: 16 Discusman User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
ASP Problem hacker related

I found these in my window's logfile
15:34:15 66.221.204.1 HEAD / 403
16:03:39 66.221.204.1 HEAD / 403
16:03:52 66.221.204.1 HEAD / 403

Now my registration form isn't working.

I believe someone loaded sort of scripts to my server and it altered something in my program.

I use IIS 5.1 with Windows XP Pro.

The registration form is blocking ppl register by saying "User name is already exist, please enter a new user name"

The error page keeps pop up even I removed that username validation line in my program.
All I get is "Http://www.mysitename.com/register.asp?ExistUserName=True"

This is not an ordinary syntax error cuz the program has been working for several month (since the date I created this form) I even get user registered yesterday. Now it stopped working today.

Could someone help? Thx.

Reply With Quote
  #2  
Old February 25th, 2004, 11:57 PM
merliin's Avatar
merliin merliin is offline
Contributing User
Dev Articles Newbie (0 - 499 posts)
 
Join Date: Feb 2004
Location: Melbourne, Australia
Posts: 30 merliin User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 7
Well it's not the HEAD / you should be worried about. That is a legal HTTP instruction, just Like GET or POST.
It's what is not in your logs that should worry you.
Check out your asp code again, make sure it's not been altered, and the same goes for the database.
Then get a trojan/virus scanner (to be on the safe side) and do a heuristic scan of your computer.
Then have a surf over at www.securityfocus.com and patch your IIS, there are a number of IIS bugs, although, the security issue at hand could just as well be caused by sql injection or unsafe redirecitions or piping. You might want to look at their article section for ASP safety good programming practices, and make sure your forms meet them.

Reply With Quote
  #3  
Old March 2nd, 2004, 08:40 AM
Discusman Discusman is offline
Registered User
Dev Articles Newbie (0 - 499 posts)
 
Join Date: Feb 2004
Posts: 16 Discusman User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Quote:
Originally Posted by merliin
Well it's not the HEAD / you should be worried about. That is a legal HTTP instruction, just Like GET or POST.
It's what is not in your logs that should worry you.
Check out your asp code again, make sure it's not been altered, and the same goes for the database.
Then get a trojan/virus scanner (to be on the safe side) and do a heuristic scan of your computer.
Then have a surf over at www.securityfocus.com and patch your IIS, there are a number of IIS bugs, although, the security issue at hand could just as well be caused by sql injection or unsafe redirecitions or piping. You might want to look at their article section for ASP safety good programming practices, and make sure your forms meet them.


Hi,

I reformatted my HD on my server. I reinstalled everything including XP and IIS 5.1.
I tried to copy all my webfiles (ASP) from my backup CD to my newly setup server.
Some of the pages get redirected to "Http://www.perfectnav.com/....uid=...... " even the ASP file is in my webroot folder.
I also found DeskTop.ini in my webroot as well as in my Server Extension Bin folder, system32 folder, etc.

How can I fix the problem?

Reply With Quote
  #4  
Old March 2nd, 2004, 08:41 AM
Discusman Discusman is offline
Registered User
Dev Articles Newbie (0 - 499 posts)
 
Join Date: Feb 2004
Posts: 16 Discusman User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
BTW, someone told me that it's normal to find DeskTop.ini in my machine.

Here is the content of DeskTop.ini in my webroot
[.ShellClassInfo]
IconFile=_vti_pvt/fpdbw.ico
IconIndex=0
ConfirmFileOp=0
InfoTip=Stores your local web site

Reply With Quote
Reply

Viewing: Dev Articles Community ForumsProgrammingASP Development > ASP Problem hacker related


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump




 Free IT White Papers!
 
Create the Optimal Architecture for your Critical Applications
Warburton's the largest independently owned bakery in the UK faced a number of difficult challenges in providing the most robust yet efficient IT infrastructure for their organization's success. IBM's services combined with their xSeries servers created the perfect platform for their SAP environment with sufficient flexibility, and did so in very time effective fashion.

Request Your Free Technology Downloads!
 
Five Best Practices for Deploying a Successful Service-Oriented Architecture
This white paper describes the benefits you can expect with SOA, and how IBM can help take your business there.

Request Your Free Technology Downloads!
 
Gartner Magic Quadrant for Application Delivery Controllers
Gartner summarizes its view on Application Delivery Controllers, evaluates strengths and weaknesses of solutions, and provides Magic Quadrant reporting for a quick comparison across all vendors. Learn from Gartner how you can benefit from an all-in-one device like Citrix NetScaler that delivers the highest levels of availability, performance and security.

Request Your Free Technology Downloads!
 
Knowledge is Power
What you don't know can hurt you, and is likely costing you money and increasing your security risks during an era of scarce resources. This white paper proposes six key strategies that enterprise security managers can use to improve their network defense posture.

Request Your Free Technology Downloads!
 
Rationalizing the Multi-Tool Environment
The rationalized multi-tool approach is flexible, scalable and cost effective. It provides the necessary input to the IT service management business processes. It preserves prior investments in monitoring tools, empowers technologists to select the best tools with which to do their jobs, and enhances effective response to incidents.

Request Your Free Technology Downloads!
 

Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 




© 2003-2010 by Developer Shed. All rights reserved. DS Cluster 7 Hosted by Hostway
For more Enterprise Application Development news, visit eWeek