RE: w2k server compromised

From: Thomas Cameron (ThomasC@mip.com)
Date: 01/24/03

  • Next message: Brothers, Sam (OCTO): "RE: w2k server compromised"
    From: Thomas Cameron <ThomasC@mip.com>
    To: focus-ms@securityfocus.com
    Date: Fri, 24 Jan 2003 09:40:18 -0600
    
    

    Don't forget to transfer the FSMO roles to the new server! You can shoot
    yourself in the foot if you just power off the old DC without transferring
    the FSMO roles.

    http://www.microsoft.com/technet/treeview/default.asp?url=/technet/prodtechn
    ol/windows2000serv/reskit/distsys/part1/dsgch07.asp

    Thomas Cameron, RHCE, CNE, MCSE, MCT
    Best Software

    -----Original Message-----
    From: james@leafgrove.com [mailto:james@leafgrove.com]
    Sent: Thursday, January 23, 2003 4:08 PM
    To: 'Dan Uscatu'; focus-ms@securityfocus.com
    Subject: RE: w2k server compromised

    Dan

    Regardless of the security implications and reasons of having an apparently
    compromised DC you can use the following procedure to get you AD databases
    copied:

    Build new W2k server box
    Harden new server
    Use DCPROMO to make it a DC in the current domain/forest
    Await replication to complete, check by directing AD Users and computers at
    the new server. Check your login scripts and policies have also come across
    by looking in SYSVOL DCPROMO old server to remove DC functionality Power off
    old server Remove entries in sites and services relating to the the old
    server if still there Remove old server computer account Rebuild old server
    Harden old server DCPROMO old server to make it a DC in the current
    domain/forest Await replication to complete, check by directing AD Users and
    computers at the old server. Check your login scripts and policies have also
    come across by looking in SYSVOL DCPROMO new server to remove DC
    functionality Power off new server Remove entries in sites and services
    relating to the the new server if still there Remove new server computer
    account Done

    Good luck and don't forget to check the rest of your LAN for pesky malware
    Of course if the compromise is AD aware you may not be able to get rid it
    this way, but that is pretty unlikely. Anyone else comment??

    Cheers

    JamesD

    -----Original Message-----
    From: Dan Uscatu [mailto:duscatu@lunatech.ro]
    Sent: 23 January 2003 08:17
    To: focus-ms@securityfocus.com
    Subject: w2k server compromised

    hey all

    i just found one of the w2k servers to be infected and acting very
    strangely. unfortunately it is a domain controller and it has all the
    users/computers lists.

    how can i export these before reinstall in order to keep the exact same
    configuration (everything except passwords of course) ? i suppose this could
    be usefull to be done on a regular basis too...

    TIA

    For the protection of our internal systems and those of our customers,
    MIP/Best Software blocks most email attachments. Please use plain text when
    corresponding via email with MIP/Best Software.



    Relevant Pages

    • Re: SBS Server keeps shutting down
      ... as we have had a few power cuts recently and the server kept chugging along. ... I have no idea what IPSec is ... multiple reboot mentioned above and some other troubleshooting steps ...
      (microsoft.public.windows.server.sbs)
    • RE: Outlook Express Connection Problem
      ... "Connection to the server has failed". ... button under Internet Connection Settings. ... Click Servers Tab; ... On the NIC properties click the Power Management Tab and Uncheck this box: ...
      (microsoft.public.windowsxp.help_and_support)
    • Re: What is easier: to delegate or to use ACLs?
      ... Joe Richards Microsoft MVP Windows Server Directory Services ... >>The reason for the delegation model isn't political. ... >>so the team with the power isn't even really working it out, ... >>folder under a project share for a server will generally have at least two ...
      (microsoft.public.windows.server.active_directory)
    • Re: Building a low-power FreeBSD media server
      ... If by "low power" you mean low power consumption (as opposed to the ... memory per TB of storage. ... and your server will be anything but low power consumption. ... generated by high density arrays of disk drives installed in the case. ...
      (comp.unix.bsd.freebsd.misc)
    • SUMMARY: Calculating power and AC requirements for a server room
      ... "What do you do for UPSes, or is that designed into the server room? ... and they have some good specs for power ... "I give our facilities guys the max current draw for each server so they ...
      (SunManagers)