System Hacked

From: malik malik (subscribejai_at_yahoo.co.uk)
Date: 08/22/03

  • Next message: Meidinger Chris: "RE: traceroute-like tool for UDP or TCP packet"
    Date: Fri, 22 Aug 2003 09:14:41 +0100 (BST)
    To: security-basics@securityfocus.com
    
    

    hi,
    Someone hacked my system.I have SMTP/POP3 running on
    Win XP and working on a LAN and have given permission
    that any one on my LAN can create account.
    Lastday someone created account and i got the message
    of new account creation and when i checked i found
    that he was trying mutiple SMTP connections TO&FROM
    fake id. i got his ip.
    When i checked the logs from Eventviewer i found that
    Administrator loggedin twice from two different ip
    using the tlntsvr.exe service thts why i am thinking
    that the ip was fake.
    Is there any way i can find out how he got access and
    how he entered through tht SMTP port and the history
    tht wht he did on getting the cmd prompt or any other
    tracing trick.
    thanks,
    jai

    ________________________________________________________________________
    Want to chat instantly with your online friends? Get the FREE Yahoo!
    Messenger http://uk.messenger.yahoo.com/

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------


  • Next message: Meidinger Chris: "RE: traceroute-like tool for UDP or TCP packet"

    Relevant Pages

    • Re: System Hacked
      ... >that any one on my LAN can create account. ... >that the ip was fake. ... >tht wht he did on getting the cmd prompt or any other ...
      (Security-Basics)
    • RE: System Hacked
      ... tlntsrv.exe is the "Telnet Server". ... Win XP and working on a LAN and have given permission ... Lastday someone created account and i got the message ... tht wht he did on getting the cmd prompt or any other ...
      (Security-Basics)
    • Re: RASd in but not fully connected
      ... Because when they do a local logon to their machine, ... This will only give them access to machines on the LAN if it ... exactly matches a valid account on the LAN. ... >>validate the connection. ...
      (microsoft.public.win2000.ras_routing)
    • Outlook ignores the specified account when sending mail
      ... The PC is connected to a LAN which sometimes has access to a DSL internet ... Outlook 2003 is a POP3 standalone configuration. ... select the LAN SMTP account from the accounts ...
      (microsoft.public.outlook.installation)
    • Re: Cracking Passwords in Mere Seconds
      ... luckily i have no down level clients, ... GPOs (with complex passwords), renaming the admin account, monitoring event ... etc...the LAN should be protected. ...
      (microsoft.public.security)