Trace of 139 attack?

From: Eagle (the_eagle@flashmail.com)
Date: 07/24/01


Message-ID: <001f01c113fc$f7b5fcf0$5903c5cb@vsnl.net.in>
From: "Eagle" <the_eagle@flashmail.com>
To: <focus-ms@securityfocus.com>
Subject: Trace of 139 attack?
Date: Tue, 24 Jul 2001 10:26:12 +0530

Hi Everyone,
Scenario:
A web server IIS 4.0 or 5.0 running on NT 4.0 or W2K.
Port 139 open and for all to see, shares in place.
All other configurations almost default.
Attacker guesses username/password of a Joe account in the Admin group.
Uses this to gain full access to the machine.
Among all the things he could possibly do, (install trojans, keyloggers,
etc), he defaces the sites, accesses sensitive
files, copies files to the system32 folder for
remote console etc.
Is there any way through reading logs etc, it might be possible to trace his
IP back? If yes, then which logs, and what entries in those logs would show
up his IP?
Remember, this has not occurred through a buffer overflow exploit, but
simply by guessing username/password.
Also prior to getting the right password, he must have gone through a number
of failed attempts. Do the logs of these give an idea of his IP?
If in the future to catch such an attack there are any config changes to be
made, then what would those be?
I'm new to this, so excuse any oversights, if this question has been asked
before. Just point me to the right resources.
Thanks
KM



Relevant Pages

  • RE: Trace of 139 attack?
    ... Subject: Trace of 139 attack? ... The Administrator account can be locked out if too many ... deleting the logs he cannot do it. ...
    (Focus-Microsoft)
  • RE: Trace of 139 attack?
    ... Subject: Trace of 139 attack? ... > deleting the logs he cannot do it. ... > If this box of yours is a web server to the world, ... > use it as file server with NetBIOS shares 'n stuff. ...
    (Focus-Microsoft)
  • FW: Trace of 139 attack?
    ... Subject: Trace of 139 attack? ... The Administrator account can be locked out if too many ... deleting the logs he cannot do it. ... use it as file server with NetBIOS shares 'n stuff. ...
    (Focus-Microsoft)
  • Re: Looking for help against Chinese Hacking Team
    ... Nowaday we can't find clue for attack. ... Finding weak web source and Fix validation problem is best way. ... somebody will have to examine the web server logs to look ... Security Trends Report from Cenzic ...
    (Pen-Test)
  • RE: Trace of 139 attack?
    ... Subject: Trace of 139 attack? ... The Administrator account can be locked out if too many ... deleting the logs he cannot do it. ... use it as file server with NetBIOS shares 'n stuff. ...
    (Focus-Microsoft)