FrontPage server extensions-security holes.....

Andrew111

Senior member
Aug 6, 2001
792
0
0
I recently noticed this show up in my website's logs:
24.26.220.12 - - [24/Jun/2003:22:33:31 -0500] "GET /_vti_inf.html HTTP/1.1" 404 808 "-" "Mozilla/2.0 (compatible; MS FrontPage 5.0)"
24.26.220.12 - - [24/Jun/2003:22:33:33 -0500] "POST /_vti_bin/shtml.exe/_vti_rpc HTTP/1.1" 404 808 "-" "MSFrontPage/5.0"
I didn't know what the hell those files were, but when I searched through Google I found this link: Security holes with FrontPage extensions I found out this person's IP is someone I know...and we recently exchanged some harsh words with each other;) I talked to him about it and he's telling me he was only previewing my site in FrontPage....but why would FrontPage need to POST anything if all it's doing is looking at the page......and that link almost seals it that he was trying to display his uber haxor skillz
rolleye.gif
I don't use FrontPage and its server extensions, so I didn't have to worry about it....is there any legitimate reason that those files would be requested in my logs?
 

Andrew111

Senior member
Aug 6, 2001
792
0
0
The only reason I don't unleash my wrath immediately is because we did have an argument about proper implementation of Flash, so he might have used FrontPage just to look at my site....but that link about FrontPage security holes is pretty clear cut and he requested the same exact files......I can't test it out myself since I'm not crazy enough to use FrontPage though:D
 

Andrew111

Senior member
Aug 6, 2001
792
0
0
No one knows what I'm talking about?:( I contacted his ISP and they actually gave him a warning....apparently he had several trojans on his computer doing port scans and all that good stuff. Would it be a stretch that the remote user who had control of his computer might have used his connection to search out FrontPage enabled sites? I hear their is supposed to be some stupid hack attack this Sunday.......I imagine it's pretty easy for them to deface sites using FrontPage extensions.