Re: data transfer

From: James B (nospam_at_here.com)
Date: 12/14/04


Date: Tue, 14 Dec 2004 17:34:50 GMT

Check your logs manually or download one of the many trialware log analyzers
for both IIS and SMTP to see if it's in there. That much data I would have
guessed somebody was using your FTP server (check your FTP default
directory) but if it's disabled and the logs don't show anything I would be
walking around to see if any of my users had installed P2P programs,
Internet radio (seems a little much for that), current virus protection,
etc.

"Johnny" <Johnny@discussions.microsoft.com> wrote in message
news:4954D121-71D0-4AFE-BE5A-D63E720AA8A6@microsoft.com...
> hi!
>
> i disabled the ftp already, and nothing changed, is there a possibility to
> log the trafic on the server?
>
> thx
> johnny
>
> "Marina Roos [SBS-MVP]" wrote:
>
> > Hi Johnny,
> >
> > You are missing the WINS on the internal nic.
> > You can delete the WINS on the external nic.
> > Are you sure you want the ftp server service running on your SBS????
> >
> > Change the nic properties, rerun CEICW and disable FTP.
> >
> > --
> > Regards,
> >
> > Marina
> > Microsoft SBS-MVP
> >
> > "Johnny" <Johnny@discussions.microsoft.com> schreef in bericht
> > news:A83690A1-D9FF-4A4A-8893-88120B26ED0B@microsoft.com...
> > > hi!
> > >
> > > ipconfig server:
> > > Windows-IP-Konfiguration
> > >
> > > Hostname . . . . . . . . . . . . : TEMASERVER
> > > Primäres DNS-Suffix . . . . . . . : tema.local
> > > Knotentyp . . . . . . . . . . . . : Unbekannt
> > > IP-Routing aktiviert . . . . . . : Ja
> > > WINS-Proxy aktiviert . . . . . . : Ja
> > > DNS-Suffixsuchliste . . . . . . . : tema.local
> > >
> > > Ethernet-Adapter Netzwerkverbindung:
> > >
> > > Verbindungsspezifisches DNS-Suffix:
> > > Beschreibung . . . . . . . . . . : Intel(R) PRO/100 M Network
> > Connection
> > > Physikalische Adresse . . . . . . : 00-0E-0C-4E-14-49
> > > DHCP aktiviert . . . . . . . . . : Nein
> > > IP-Adresse. . . . . . . . . . . . : 192.168.120.200
> > > Subnetzmaske . . . . . . . . . . : 255.255.255.0
> > > Standardgateway . . . . . . . . . : 192.168.120.254
> > > DNS-Server . . . . . . . . . . . : 192.168.110.200
> > > Primärer WINS-Server . . . . . . : 192.168.110.200
> > > NetBIOS über TCP/IP . . . . . . . : Deaktiviert
> > >
> > > Ethernet-Adapter LAN-Verbindung des Servers:
> > >
> > > Verbindungsspezifisches DNS-Suffix:
> > > Beschreibung . . . . . . . . . . : Intel(R) PRO/1000 CT Network
> > Connection
> > > Physikalische Adresse . . . . . . : 00-0E-0C-4E-14-48
> > > DHCP aktiviert . . . . . . . . . : Nein
> > > IP-Adresse. . . . . . . . . . . . : 192.168.110.200
> > > Subnetzmaske . . . . . . . . . . : 255.255.255.0
> > > Standardgateway . . . . . . . . . :
> > > DNS-Server . . . . . . . . . . . : 192.168.110.200
> > >
> > > ipconfig client:
> > > Windows-IP-Konfiguration
> > >
> > > Hostname. . . . . . . . . . . . . : tema03
> > > Primäres DNS-Suffix . . . . . . . : tema.local
> > > Knotentyp . . . . . . . . . . . . : Hybrid
> > > IP-Routing aktiviert. . . . . . . : Nein
> > > WINS-Proxy aktiviert. . . . . . . : Nein
> > > DNS-Suffixsuchliste . . . . . . . : tema.local
> > > tema.local
> > >
> > > Ethernetadapter LAN-Verbindung:
> > >
> > > Verbindungsspezifisches DNS-Suffix: tema.local
> > > Beschreibung. . . . . . . . . . . : 3Com EtherLink XL 10/100
> > > PCI-TX-NIC
> > > (3C905B-TX)
> > > Physikalische Adresse . . . . . . : 00-10-5A-B2-35-B2
> > > DHCP aktiviert. . . . . . . . . . : Ja
> > > Autokonfiguration aktiviert . . . : Ja
> > > IP-Adresse. . . . . . . . . . . . : 192.168.110.22
> > > Subnetzmaske. . . . . . . . . . . : 255.255.255.0
> > > Standardgateway . . . . . . . . . : 192.168.110.200
> > > DHCP-Server . . . . . . . . . . . : 192.168.110.200
> > > DNS-Server. . . . . . . . . . . . : 192.168.110.200
> > > Primärer WINS-Server. . . . . . . : 192.168.110.200
> > > Lease erhalten. . . . . . . . . . : Dienstag, 14. Dezember
2004
> > > 12:01:19
> > >
> > > Lease läuft ab. . . . . . . . . . : Mittwoch, 22. Dezember
2004
> > > 12:01:19
> > >
> > > 2 nics, firewall services: email, terminal, ftp
> > > from internet: owa
> > >
> > > on the router (netgear fvs318) ports 3389 and 443 to 192.168.120.200
> > >
> > > thats it!
> > >
> > > thx
> > >
> > > johnny
> > > "Marina Roos [SBS-MVP]" wrote:
> > >
> > > > Hi Johnny,
> > > >
> > > > Please post the ipconfig/all from the server and a client. Which
> > services
> > > > did you enable during CEICW?
> > > >
> > > > --
> > > > Regards,
> > > >
> > > > Marina
> > > > Microsoft SBS-MVP
> > > >
> > > > "Johnny" <Johnny@discussions.microsoft.com> schreef in bericht
> > > > news:1FFE378E-41B2-4F14-A58B-7725C148ABEA@microsoft.com...
> > > > > hi!
> > > > >
> > > > > i installed a sbs 2003, exchange, pop3 connector,
> > > > >
> > > > > after the installation works fine, i thought everything is all
right,
> > but
> > > > > after a few days i recognized, that there is a lot of data
transfer,
> > which
> > > > i
> > > > > can´t say where it comes from (approximatly 400mb download, 600mb
> > upload a
> > > > > day).
> > > > >
> > > > > this must be caused by the server, because it is also on days when
no
> > > > > clients are connected.
> > > > >
> > > > > please help
> > > >
> > > >
> > > >
> >
> >
> >



Relevant Pages

  • Re: FTP files dissappearing!!
    ... I don't see any reason why you couldn't also easily enable a free sniffer to ... you should be able to enable FTP logging and logging on your ... Synchronizing the time on your FTP server and firewall ... and then correlating the two logs may help you determine which IP address is ...
    (microsoft.public.inetserver.iis.security)
  • Re: Sendmail Hacked
    ... > connection which is weird because I didn't know I had ftp running. ... I checked the ftp logs and they've all been cleared. ... They trace the spam back to you by the ... need sendmail running, or FTP, or telnet. ...
    (comp.os.linux.security)
  • [Full-disclosure] Ipswitch FTP XSS leads to FTP server compromise
    ... Ipswitch FTP XSS leads to FTP server compromise. ... There is XSS vulnerability when the WS_FTP server logs client FTP ... We've created a little PoC that will create a new system administrator ...
    (Full-Disclosure)
  • Re: Help -- Have I been rooted?
    ... I only allowed ssh, httpd, and ftp port forwarding to my ... machine for the past few days while I used a store bought router. ... I checked the router logs and was greeted by pages of stuff like this: ...
    (comp.os.linux.security)
  • Re: Question on Internet access of vsftp server
    ... > Pete Nesbitt wrote: ... >> you should check your logs, and also add a LOG entry to the firewall DENY ... >>Depending on your exact rules, add something like this, just blow your FTP ...
    (RedHat)

Quantcast