RE: IIS web server hacked..any tips?

From: Curt Purdy (purdy_at_tecman.com)
Date: 12/15/04

  • Next message: xyberpix: "Re: IIS web server hacked..any tips?"
    To: "'Francesco'" <francesco@blackcoil.com>, <incidents@securityfocus.com>
    Date: Wed, 15 Dec 2004 15:11:29 -0600
    
    
    

    Francesco wrote:
    > Yesterday someone managed to access the server and dump 8GB
    > of DVD files into a deeply nested folder in a backup
    > directory, for sharing I presume. The payload folder was NOT
    > within the available folders given access to FTP users.
    > Someone was able to "see" the entire D drive and figure out a
    > hidden enough location at their whimsy.
    <snip>

    Tip? Use Apache on *NIX ;)

    Seriously though, you will need to remove those folders manually. Some will
    likely have names like COM and LPT1 which *NIX is fine with but windoze
    chokes on. Attached is the description how to (only 3k so am attaching to
    everyone).

    As for how they did it, you are running some of the biggest problems MS has
    including IIS, SQL Server, and ASP.NET, any one of which could be
    exploitable. You cannot rely on windowsupdate to tell you your patched. It
    often lies because it only looks at the registry which is updated prior to
    the actual update completing (can you say dumb?). You must run multiple
    tests like MBSA to verify.

    In addition there are possibly 3rd part programs loaded that need patching.
    The only time my windoze server got hacked was when a cracker exploited a
    vuln in Matt's formmail perl script we were using.

    Also, I would look at the times of file install to determine whether it was
    internal or external. If times are too close for your Internet line to
    accommodate, it means you have an insider to contend with once you clean up
    your act. If that is the case, you may want to take the box offline by
    pulling the plug (that leaves everything in virtual memory intact for
    forensic analysis) and determine who needs to be fired.

    Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA
    Information Security Engineer
    DP Solutions

    ----------------------------------------

    If you spend more on coffee than on IT security, you will be hacked.
    What's more, you deserve to be hacked.
    -- former White House cybersecurity czar Richard Clarke

    
    



  • Next message: xyberpix: "Re: IIS web server hacked..any tips?"

    Relevant Pages

    • Re: Email enable doc lib
      ... navigate to the public folder and send some posts with attachments to the ... Microsoft CSS Online Newsgroup Support ... I have disabled forms base Athentication from the default V.Smtp server ...
      (microsoft.public.windows.server.sbs)
    • Re: Newbie with a smallbiz2000 installation, check my config?
      ... > Windows creates a profile path under Documents & Settings. ... > a folder with that name already exists (maybe a local user with the ... > server, open the properties for this folder, and ensure that you have ... > you redirect key folders from a user's profile to a location on your ...
      (microsoft.public.backoffice.smallbiz2000)
    • Re: Network shares cannot connect
      ... User Name: SERVER$ ... Regarding the shares accessing problem, I suggest you try following steps ... let's focus on the Users Shared Folder first. ... To check this permission, please click the Advanced button, select ...
      (microsoft.public.windows.server.sbs)
    • Re: Disappearing disk space?
      ... I switched off the AV scanning completely last night and the ... Windows Server 2003, Windows 2000, or Windows XP ... %systemroot%\Sysvol folder ... KB309422 - Guidelines for choosing antivirus software to run on the ...
      (microsoft.public.windows.server.sbs)
    • Re: SBS 2003 folder redirection, offline files, ..and more
      ... you log into a shared PC with admin rights and go to Windows Explorer Folder ... documents are redirected to the server. ... without redirection, they wouldn't have been. ...
      (microsoft.public.windows.server.sbs)