Click here to get back home

Services disabled by itself

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Services disabled by itself Emyeu 03-01-2006
Get Chitika Premium
Posted by Emyeu on March 1, 2006, 8:40 pm
Please log in for more thread options
for the past one week, i always have problem on some of my websites servers
which "World Wide Web Publishing " and "IIS Admin" services disabled by
itself. Those web servers are released to the public.
Both services are set to "Automatic" in the Startup Type. However, the
services was 'Stopped' and changed to "Disabled" by itself.
Could it be Denial-of-Service attack?



Posted by Roger Abell [MVP] on March 1, 2006, 8:55 pm
Please log in for more thread options
One would not classify that as a denial of service attack, which
normally is just plugging up a key resource so it cannot complete
its task. Rather, if this is due to some outside agent one would
just call it a compromise of the system, since to make the change
you report someone/something must be running with admin or
system.

Are these servers in a domain ??
Have you examined what might be happening from GPO setting
of services from Active Directory if they are ?


> for the past one week, i always have problem on some of my websites
> servers
> which "World Wide Web Publishing " and "IIS Admin" services disabled by
> itself. Those web servers are released to the public.
> Both services are set to "Automatic" in the Startup Type. However, the
> services was 'Stopped' and changed to "Disabled" by itself.
> Could it be Denial-of-Service attack?
>
>



Posted by Emyeu on March 1, 2006, 9:12 pm
Please log in for more thread options
Those servers are member of the Domain.
Problem doesn't happened all at the same time! It happened anytime of the
day.


> One would not classify that as a denial of service attack, which
> normally is just plugging up a key resource so it cannot complete
> its task. Rather, if this is due to some outside agent one would
> just call it a compromise of the system, since to make the change
> you report someone/something must be running with admin or
> system.
>
> Are these servers in a domain ??
> Have you examined what might be happening from GPO setting
> of services from Active Directory if they are ?
>
>
>> for the past one week, i always have problem on some of my websites
>> servers
>> which "World Wide Web Publishing " and "IIS Admin" services disabled by
>> itself. Those web servers are released to the public.
>> Both services are set to "Automatic" in the Startup Type. However, the
>> services was 'Stopped' and changed to "Disabled" by itself.
>> Could it be Denial-of-Service attack?
>>
>>
>
>



Posted by Roger Abell [MVP] on March 2, 2006, 8:28 pm
Please log in for more thread options
If it is coming from AD based group policy, each machine applies
this on its own schedule, roughly each 90 minutes.
If you can rule out GPOs doing this through policy then you are
going to have to track it down based on event log messages and
what is running, what accounts are logged in (locally or over net).

> Those servers are member of the Domain.
> Problem doesn't happened all at the same time! It happened anytime of the
> day.
>
>
>> One would not classify that as a denial of service attack, which
>> normally is just plugging up a key resource so it cannot complete
>> its task. Rather, if this is due to some outside agent one would
>> just call it a compromise of the system, since to make the change
>> you report someone/something must be running with admin or
>> system.
>>
>> Are these servers in a domain ??
>> Have you examined what might be happening from GPO setting
>> of services from Active Directory if they are ?
>>
>>
>>> for the past one week, i always have problem on some of my websites
>>> servers
>>> which "World Wide Web Publishing " and "IIS Admin" services disabled by
>>> itself. Those web servers are released to the public.
>>> Both services are set to "Automatic" in the Startup Type. However, the
>>> services was 'Stopped' and changed to "Disabled" by itself.
>>> Could it be Denial-of-Service attack?
>>>
>>>
>>
>>
>
>



Posted by Emyeu on March 5, 2006, 9:21 pm
Please log in for more thread options
i think it is due to the GPO!
i moved the Web servers computer objects to other OU and now services don't
disabled anymore. but i cannot find any setting in GPO that disabled web
services. where exactly the setting is?


> If it is coming from AD based group policy, each machine applies
> this on its own schedule, roughly each 90 minutes.
> If you can rule out GPOs doing this through policy then you are
> going to have to track it down based on event log messages and
> what is running, what accounts are logged in (locally or over net).
>
>> Those servers are member of the Domain.
>> Problem doesn't happened all at the same time! It happened anytime of the
>> day.
>>
>>
>>> One would not classify that as a denial of service attack, which
>>> normally is just plugging up a key resource so it cannot complete
>>> its task. Rather, if this is due to some outside agent one would
>>> just call it a compromise of the system, since to make the change
>>> you report someone/something must be running with admin or
>>> system.
>>>
>>> Are these servers in a domain ??
>>> Have you examined what might be happening from GPO setting
>>> of services from Active Directory if they are ?
>>>
>>>
>>>> for the past one week, i always have problem on some of my websites
>>>> servers
>>>> which "World Wide Web Publishing " and "IIS Admin" services disabled by
>>>> itself. Those web servers are released to the public.
>>>> Both services are set to "Automatic" in the Startup Type. However, the
>>>> services was 'Stopped' and changed to "Disabled" by itself.
>>>> Could it be Denial-of-Service attack?
>>>>
>>>>
>>>
>>>
>>
>>
>
>



Similar ThreadsPosted
IPSec NAT-T disabled on SP2 September 19, 2005, 12:11 pm
"Who disabled the user" problem March 28, 2007, 9:38 pm
Inherited Permissions disabled? October 12, 2007, 9:16 pm
Disabled Domain Computer Accounts September 20, 2006, 4:09 pm
server2008 password expiration disabled? February 28, 2008, 7:00 pm
PCs still function on domain with computer account disabled June 14, 2006, 3:51 pm
Logon to Windows disabled on Vista Remote Desktop December 12, 2007, 9:30 pm
Server 2003 sp1 - DCOM 'Edit Limits' button disabled June 17, 2005, 2:42 pm
Administrator account disabled but still get "incorrect password" errors in Event log May 4, 2008, 2:11 pm
Administrator account disabled but still get "incorrect password" errors in Event log May 4, 2008, 2:12 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap