RE: Hacked Server



Hi Geoff,

What do your logs say ? Failed logons is proof that Mr Hacker didn't logon.
Also, I doubt any hacker worth his salt would only shut down the server when
he could so easily destroy data etc. Have you got a UPS installed and is the
sensitivity set to high (I had this same problem - my server shut down every
morning at around 0600 because the power fluctuates at that time and the UPS
did it's job thinking the power was about to go down). ? The logs should tell
you what time the server is shutting down. If it's the same time you could
have a similar problem to me or it could be a service that is running and
causing the shut down. Is WSUS set to install updates on the server
automatically for example ?

Regards Colin.

"Geoff" wrote:

Hello All,

We run a SBS 2003 Box with 2 NIC connected to the net via a fairly std ADSL
Router. Two days ago I saw a lot of failed logon attempts in the logs.
Yesterday when I came in the server had been shut down.

I renamed the admin account and changed the password, closed all router
ports appart from VPN, and RWW ran full scans for viruses trojans etc
disabled all remote access permissions for all other accounts.

This morning its happened again? I have to assume that whoever did this the
first time left some back door that I did not find so they could do it again.

Can anyone point me in the right direction?

Thanks

Geoff
.



Relevant Pages

  • RE: isa 2004 & external website access issue
    ... emailed the logs to you as requested. ... each web server has its own public IP ... > headers in ISA Server ... > 'Microsoft Firewall' service. ...
    (microsoft.public.windows.server.sbs)
  • RE: Exchange Server
    ... I researched your logs and found the MSExchangeTransport events 4006, 969, ... Right click Default SMTP Virtual Server and select Properties. ... Microsoft CSS Online Newsgroup Support ... This newsgroup only focuses on SBS technical issues. ...
    (microsoft.public.windows.server.sbs)
  • RE: OWA 2003 with ISA 2004
    ... OWA externally. ... i can login by any user. ... 825763 How to configure Internet access in Windows Small Business Server ... g. Reproduce this issue and send the logs to me. ...
    (microsoft.public.windows.server.sbs)
  • RE: OWA 2003 with ISA 2004
    ... I understand that you can not login OWA from ... 825763 How to configure Internet access in Windows Small Business Server ... g. Reproduce this issue and send the logs to me. ... and then right click 'Microsoft Firewall' to ...
    (microsoft.public.windows.server.sbs)
  • RE: VPN, RRAS & DHCP
    ... After researching your logs, I found the Event ID 20169 ... Please try to set RemoteAccess service to depend on the DHCP server ... Reboot the server to see whether the issue still occurs. ... The problem occurred after you install ISA server. ...
    (microsoft.public.windows.server.sbs)