Live data from Hacker News

Humiliating IIS servers for fun and jail time

mll.sh

91–100 of 106 posts

Re: Humiliating IIS servers for fun and jail time

#91
post #45

Earlier quoted context omitted.

Really simple. I read the prerequisites of whatever software im asked to install and do what it says. I'm not spending the next 3 years of my life trying to make some monitoring platform run on WebLogic i have other jobs to do in 4-8-12 hours.

this is one of the funniest recurring threads on HN. developers finding out what other developers are requiring from their customers. Bonus points for developers finding out that non-cloud solutions still dominate some industries.

Cloud's got nothing to do with it. The thought of standing up a windows box to serve anything other than profiles and user surveillance is simply foreign. Budget webhosting has been a thing for a long time and standing up a *nix VM is also no big deal. In 25 years in industry I never once saw an IIS server used in the wild. shrug

Re: Humiliating IIS servers for fun and jail time

#95

Earlier quoted context omitted.

Sounds like creating an url like aspnet_client/admin.php returning a WebObjects header might be a good hobby

Add in a zip bomb or two?

Now you have me wondering how badly http gzip content compression can be abused along those lines.

Re: Humiliating IIS servers for fun and jail time

#96
post #81

Earlier quoted context omitted.

HN guidelines ask you to not do this. > Please don't complain about tangential annoyances—e.g. article or website formats, name collisions, or back-button breakage. They're too common to be interesting. While few read them, it might be helpful if @dang threw in the ", or LLM generated content".

HN guidelines also say that HN is for conversation between humans. If we are having a conversation with the author through their article, then the prose should be human too. :^)

The 'humans' guidelines are under Comments, not Posts. ;-)

Re: Humiliating IIS servers for fun and jail time

#97

Earlier quoted context omitted.

this is one of the funniest recurring threads on HN. developers finding out what other developers are requiring from their customers. Bonus points for developers finding out that non-cloud solutions still dominate some industries.

Cloud's got nothing to do with it. The thought of standing up a windows box to serve anything other than profiles and user surveillance is simply foreign. Budget webhosting has been a thing for a long time and standing up a *nix VM is also no big deal. In 25 years in industry I never once saw an IIS server used in the wild. shrug

I'm surprised by this, maybe its industry specific.

An 80:20 split of windows server to everything else has been pretty common in the areas I've worked both as a <10 day contactor and as a FTE.

Re: Humiliating IIS servers for fun and jail time

#98
post #77
post #71

Oh man this takes me back. Once upon a time, all server logs were basically unusable because of the amount of IIS scanners out there. There was a directory traversal that was literally just url encoding “../“ that absolutely lit the internet on fire for many months.

Those traversal attempts are still very common, right next to the PHP/WordPress script kiddie attacks.

"The White Noise of the Internet" as they call it

Re: Humiliating IIS servers for fun and jail time

#99
post #21

Earlier quoted context omitted.

Tell me more…I opened a plex and Nintendo switch port, the scans were out of control. I’d love to screw over port scanner over.

What does shodan.io run?

Not sure but the IPs don’t come back as Chinese and the dns registries, domains, and other data I could find was generated using US address data. Lots of stuff like 123 stree, where half the address was truncated.

Re: Humiliating IIS servers for fun and jail time

#100
post #59

Earlier quoted context omitted.

That's just security by obscurity, which is rated pretty appropriately.

Obscurity is a perfectly adequate layer of security. It shouldn't be the only layer but those who argue against adding it heard at some point "security through obscurity is not security" and never dug deeper.

... those who argue against adding it heard at some point "security through obscurity is not security" and never dug deeper.

Ironically, that makes them the exact type of person who would be successfully deterred by a layer of obscurity.

Post reply on HN