Tech or Treat! Write an article about your scariest tech disaster to win gadgets!Learn more

x
?
Solved

Denial of Service Attacks

Posted on 2010-09-06
4
Medium Priority
?
574 Views
Last Modified: 2012-05-10
I've just had a request from an old client, (site created 8 yrs ago) that he's having a DOS problem, the site was one of my last asp sites and the info he has sent me is shown below.

Can anyone explain this? Help resolve it or is it a case of a rewrite to ASP.NET in which case I need help with the justification!

The attack scenario is thus:

"Some server sends a request like

index.php?option=com_product&controller=../../../../../../../../../../../../
../../../proc/self/environ%00

This makes your IIS server panic and it uses greater than 100% CPU! The type of request is a DOS (Denial of Service) attack, but it looks like a DOS attack for a Unix based machine, not a Windows machine, but it is crippling your server.

It's something to do with your server not being able to handle a "querystring" (to the right of the "?") with a multiple "up directory" ( the ".." parts) - or maybe just one "up directory".

I've been trying to find something that would redirect the above line to something else (or reject it), but not being successful.

I've heard that this problem can be caused by "bad code" - I've written a dummy index.php on your server, but the crash is caused *before* it even requests the index.php page - so I don't think it's a "bad coding" issue!"

Mark
0
Comment
Question by:markej
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 9

Accepted Solution

by:
shalabhsharma earned 1000 total points
ID: 33612554
0
 
LVL 11

Expert Comment

by:madgino
ID: 33613087
PHP version? IIS version? OS?
 I would suggest an upgrade of php and latest patches for IIS/OS.
0
 
LVL 11

Assisted Solution

by:madgino
madgino earned 1000 total points
ID: 33613125
0
 

Author Closing Comment

by:markej
ID: 33757470
I'm not a Sys Admin, I offered my help to an old client and realised I was out of my depth and wanted some specific answers so I could instrhim on what to do!
0

Featured Post

Survive A High-Traffic Event with Percona

Your application or website rely on your database to deliver information about products and services to your customers. You can’t afford to have your database lose performance, lose availability or become unresponsive – even for just a few minutes.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Running classic asp applications under Windows Server 2008 R2 (x64) and IIS 7 is not as easy as one may think. It took me a while to figure it out while getting error 8002801d a few times. After you install the OS you will need to install the fol…
International Data Corporation (IDC) prognosticates that before the current the year gets over disbursing on IT framework products to be sent in cloud environs will be $37.1B.
In this video, Percona Solution Engineer Dimitri Vanoverbeke discusses why you want to use at least three nodes in a database cluster. To discuss how Percona Consulting can help with your design and architecture needs for your database and infras…
Want to learn how to record your desktop screen without having to use an outside camera. Click on this video and learn how to use the cool google extension called "Screencastify"! Step 1: Open a new google tab Step 2: Go to the left hand upper corn…

648 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question