473,325 Members | 2,860 Online
Bytes | Software Development & Data Engineering Community
Post Job

Home Posts Topics Members FAQ

Join Bytes to post your question to a community of 473,325 software developers and data experts.

IIS Log for Website reports 401 error on GET '/'

This guy is likely just a hacker, or probing to see our 401/404 page.

However how can he do this? I cannot reproduce it.

The Log: 2 different times but here is one
2008-02-13 20:52:57 172.16.0.30 GET / - 80 - 209.4.20.34 - 401 1 64

However if I telnet and do a get:
Connect: 172.16.0.30 (local IP address for website)
Port: 80

GET / HTTP/1.1
host: www.xxxxx.com

I'll get my Index.html page. This is what it looks like in the log

2008-02-14 16:06:02 172.16.0.30 GET /index.html - 80 - 172.16.1.16 - 200 0 0

or

GET / HTTP/1.0

I'll again get my index.html page.

I tried putting in special characters

GET /_ HTTP/1.0

then I get a 404 page.

But how is this guy able to get it to not direct '/' to 'index.html'... and he gets a 401 error?
Feb 14 '08 #1
4 4106
kenobewan
4,871 Expert 4TB
If this guy is a hacker and getting a 401 - perfect - access denied. You may not be able to replicate if you have the right permissions.
Feb 15 '08 #2
If this guy is a hacker and getting a 401 - perfect - access denied.
This is a public website. So everybody even on the outside should have 'The Right Permissions'.

I don't understand how he would get the 401 error... just doing a 'GET' on ' / '
When the site automatically see's ' / ' as the index page. I did a search in the history of hits to the site. There was one other time, and another IP address that also received the 401 error on ' / '.

Are they sending a bad authentication request, even though authentication is not required? I wanna know how they get there... or if for some reason the IIS is not changing ' / ' to index for some reason in the case of a couple of IP addresses.
Feb 15 '08 #3
kenobewan
4,871 Expert 4TB
My two guesses are that he is trying he is trying to query your database or the directory has a problem. The second seem less likely on a site that is already up and running. Although directory listing can be access denied when there is not a default file in that folder. The right permissions to give a site are anonymous access which denies access to other areas of the application/ server. HTH.
Feb 16 '08 #4
Directory listing denied error is 403... is it not? That is not what is happening here. The default page is index... so that is what I'm complaining about, is how is it that he goes for 'GET /' and gets a 401 instead of the default page?

I got another one on Sat the 16th. From the same IP. He is sending some sort of special character or something to cause it not to see the GET / as GET index. Or even more likely as stated in the last mesg... he is sending authentication that is purposely wrong. I'm attempting to duplicate that as I speak.

As stated when I send a manual 'GET /' to the website... in the log it comes out get index. Then in the text in the TELNET window I get the text of the index.html page.

so he is formatted his GET string different and somehow bypassing IIS directive to go to the default Index page. Yet in the log it is logged as just 'GET /'
Feb 18 '08 #5

Sign in to post your reply or Sign up for a free account.

Similar topics

9
by: Xueilonox | last post by:
I'm working on a project that has a website with some streaming video. We're tracking clicks on the custom video player (Windows Media Player) to a mysql database (requirement). Is there a...
11
by: lkrubner | last post by:
We are working on a website that is here: http://www.lauradenyes.com/ The site was working till I put up an .htaccess file that was suppose to redirect all html files to the PHP parser. The...
0
by: Ian | last post by:
(Sorry if I have repeated this, it did not appear the first time) I have the following code on a button. The idea is that when this button is clicked it prints several reports automatically then...
1
by: intl04 | last post by:
I am getting strange print-related error messages when trying to create (not print!) reports. For example, when I click 'new' to create a report then choose 'design view', I get an error message...
7
by: dog | last post by:
I've seen plenty of articles on this topic but none of them have been able to solve my problem. I am working with an Access 97 database on an NT4.0 machine, which has many Access reports. I...
11
by: Grasshopper | last post by:
Hi, I am automating Access reports to PDF using PDF Writer 6.0. I've created a DTS package to run the reports and schedule a job to run this DTS package. If I PC Anywhere into the server on...
5
by: Craig | last post by:
I get an error when compiling the website about the first Reports folder. If I change the name the website compiles. Am I doing something wrong?? Folder list...... CoolingTower Boilers...
10
by: Sridhar | last post by:
HI, I am having problems setting up a website so that it will be available only inside the domain. We have three servers. One is iis server and second one is internal server and the third one is...
5
by: Peter | last post by:
IIS6 on Windows Server 2003 I have a DotNetNuke website which works fine as long as I am openning the webpage on the web server, but when I try to open the same website from any client the...
0
by: DolphinDB | last post by:
Tired of spending countless mintues downsampling your data? Look no further! In this article, you’ll learn how to efficiently downsample 6.48 billion high-frequency records to 61 million...
0
by: ryjfgjl | last post by:
ExcelToDatabase: batch import excel into database automatically...
0
isladogs
by: isladogs | last post by:
The next Access Europe meeting will be on Wednesday 6 Mar 2024 starting at 18:00 UK time (6PM UTC) and finishing at about 19:15 (7.15PM). In this month's session, we are pleased to welcome back...
1
isladogs
by: isladogs | last post by:
The next Access Europe meeting will be on Wednesday 6 Mar 2024 starting at 18:00 UK time (6PM UTC) and finishing at about 19:15 (7.15PM). In this month's session, we are pleased to welcome back...
0
by: Vimpel783 | last post by:
Hello! Guys, I found this code on the Internet, but I need to modify it a little. It works well, the problem is this: Data is sent from only one cell, in this case B5, but it is necessary that data...
1
by: PapaRatzi | last post by:
Hello, I am teaching myself MS Access forms design and Visual Basic. I've created a table to capture a list of Top 30 singles and forms to capture new entries. The final step is a form (unbound)...
1
by: Defcon1945 | last post by:
I'm trying to learn Python using Pycharm but import shutil doesn't work
0
by: Faith0G | last post by:
I am starting a new it consulting business and it's been a while since I setup a new website. Is wordpress still the best web based software for hosting a 5 page website? The webpages will be...
0
isladogs
by: isladogs | last post by:
The next Access Europe User Group meeting will be on Wednesday 3 Apr 2024 starting at 18:00 UK time (6PM UTC+1) and finishing by 19:30 (7.30PM). In this session, we are pleased to welcome former...

By using Bytes.com and it's services, you agree to our Privacy Policy and Terms of Use.

To disable or enable advertisements and analytics tracking please visit the manage ads & tracking page.