Re: Hacked Server

Tech-Archive recommends: Fix windows errors by optimizing your registry



"Geoff" <Geoff@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:D38D4538-8AED-432A-8F62-5303EDED5EF0@xxxxxxxxxxxxxxxx
Hello All,

We run a SBS 2003 Box with 2 NIC connected to the net via a fairly std
ADSL
Router. Two days ago I saw a lot of failed logon attempts in the logs.
Yesterday when I came in the server had been shut down.

I renamed the admin account and changed the password, closed all router
ports appart from VPN, and RWW ran full scans for viruses trojans etc
disabled all remote access permissions for all other accounts.

This morning its happened again? I have to assume that whoever did this
the
first time left some back door that I did not find so they could do it
again.

Can anyone point me in the right direction?

If you go back through the event logs do you see a reason for why it was
shutdown? Was it unexpected, ie hardware or power failure or a "normal"
shutdown?

If you think it might be someone connecting from the internet, then why not
power down the router over night and see if still happens. (Assuming you use
Exchange then you shouldn't lose emails for one night's downtime, they
should remain queued up by the sending server - but it might be inconvenient
for those using VPN and RWW.)

Another suggestion, if you think that you might have an account that has
been hacked then I suggest you force *all* users with any form of remote
access to change their passwords. Thinking of which, according to the logs
was anyone connected remotely when the server when down?
--
Brian Cryer
www.cryer.co.uk/brian


.



Relevant Pages

  • Re: linksys router
    ... UPnP is enabled. ... but have you tried Enabling UPnP on that router? ... >> I have the same router at home and connecting via Remote Desktop or ... Forget about the Remote Desktop stuff, ...
    (microsoft.public.windowsxp.network_web)
  • Re: linksys router
    ... > The MTU configurable would be enabled and configured if the router is ... According teo Linksys, the latest firmware IS installed, although I have not ... All of this remote desktop stuff aside, I can not get to teh log on screen ... >> I have the same router at home and connecting via Remote Desktop or ...
    (microsoft.public.windowsxp.network_web)
  • Re: Local Group Policy mistake.
    ... I am unsure of the local admin account status connecting ... But back to connecting, it won't ping the machine..this seems to be a result ... I am assuming that you have remote admin rights over the machine? ... refresh policy, those SRP settings will be removed. ...
    (microsoft.public.windows.group_policy)
  • Re: 1 way remote desktop
    ... Can I edit my lan network on the desktop and add one? ... If not, is Remote ... >Note that port forwarding on the router has no bearing ... >> Please try connecting again later. ...
    (microsoft.public.windowsxp.work_remotely)
  • linksys router
    ... Linksys BESFR41v4 4-port wired router. ... I have the same router at home and connecting via Remote Desktop or WIN-VNC ...
    (microsoft.public.windowsxp.network_web)