Detecting compromised systems?

From: Michele (mycorner6@yahoo.com)
Date: 01/16/03


From: mycorner6@yahoo.com (Michele)
Date: 16 Jan 2003 11:50:57 -0800

I am trying to help a company that currently has all their servers and
desktops directly connected to the Internet. They are unwilling to
rebuild their machines to move them behind a firewall, but instead
want to know how to detect which systems may have been compromised,
and attempt to correct those. If there is a system showing a sign of
unrecoverable compromise, they are willing to rebuild it.

Are there any suggestions for how to detect Windows desktops and
servers that may have been compromised?

Thanks in advance, for the advice and the flames. :-)

-Michele



Relevant Pages

  • Re: Detecting compromised systems?
    ... If there is a system showing a sign of ... >unrecoverable compromise, they are willing to rebuild it. ... >servers that may have been compromised? ...
    (comp.security.misc)
  • RE: Microsoft Security Advisory MS 03-007
    ... announcement covers IIS 5.1 but not IIS 6, ... > You say "IIS servers are actively being compromised already, ... through, and if it carried the exploit, compromise could occur. ... CONFIGURATIONS OF THE IIS LOCKDOWN TOOL DO LEAVE WEBDAV ...
    (Focus-Microsoft)
  • Rebuilding a license server
    ... I have two Win2000 servers to rebuild ... Both machines are AD domain controllers, ... Talent hits a target no one else can hit. ...
    (microsoft.public.windows.terminal_services)
  • Re: Pasword compromised.
    ... eBays own servers containing password matches ... which might compromise whole groups of passwords of ... suggestion that the records on eBay's servers had merely ... from credit card company's systems. ...
    (uk.people.consumers.ebay)
  • Re: Max number of documents / performance
    ... SQL 2000 supports something called change tracking which will ... Looking for a SQL Server replication book? ... Some of my servers are running SQL2000, and a few new ones are running ... to the index without a complete index rebuild, ...
    (microsoft.public.sqlserver.fulltext)