Hi everyone,

Here is a peice of an IIS 6 log file of a recently defaced site.

##after a few failed attempts this one was successful
2006-05-25 04:57:20 POST /_vti_bin/shtml.dll/_vti_rpc - - HTTP/1.1 MSFrontPage/5.0 - 200 349
2006-05-25 04:57:20 POST /_vti_bin/_vti_aut/author.dll - - HTTP/1.1 MSFrontPage/5.0 - 200 1107
2006-05-25 04:57:25 POST /_vti_bin/shtml.dll/_vti_rpc - - HTTP/1.1 MSFrontPage/5.0 - 200 348
2006-05-25 04:57:25 POST /_vti_bin/_vti_aut/author.dll - - HTTP/1.1 MSFrontPage/5.0 - 200 1189

## here comes zone-h about a minute later
2006-05-25 04:58:01 GET /Default.htm - - HTTP/1.0
Wget/1.9.1 - 200 1930
2006-05-25 04:58:03 HEAD /Default.htm - - HTTP/1.0
Sprint+( - 200 355

I know that this is somewhat a joke of an attack.

The ftp logs were missing for this day and a few days after.

I traced the Ip to a Brazilian ISP. The group is called "SPYKIDS".
They have many defacements credited to them.

Here is my question. Where else can I find evidence on the server to
support my findings.

Findings: Exploited vulnerability in FrontPage extentions

I have not been to the server I have only reviewed the IIs logs at this point.

This server was not in the path of IDS or even in a DMZ. The internal
network is one flat segment. Client and servers on the same segment.

During my log review I found many attempts using different techniques
to gain a foothold on this server via IIS.

My other concern is how long was it vulnerable. Was this the first
attacker to leave his calling card?

Has it compromised for a long time?

Being the devil's advocate that I am, I could ask alot of questions.

If anyone has dealt with this particular attack before or performed it
;-) please shed a little more light for me.

TIA - secret_squirrel

