Re: server is being hacked



"joseph.rosario@xxxxxxxxx" <joseph.rosario@xxxxxxxxx> writes:

every month I am finding either one or two services that are hack
services. I delete the files and clean the service in the registry
then between 1 and 3 months a new hack is on my server. I have
symantec 10.2 and symantec for exchange and a barracuda on the outside
of my network. Can any one help to find the root of this issue. I use
the normal tools like rootkit revealer and aports for scanning my
ports but still they get in. I check my server a few times a day and
usually I catch it within a day but that might be to late. My updates
and patches are up to date. I am running SBS 2003 sp2 and exchange
2003 sp1.


Hi Joseph,

Sorry to hear of your struggles. You need to follow the standard
procedure for recovering from a malware infection:
o remove teh box from the network
o pull data off to another advice and/or image the drive
(including slack space) for later reference or a forensic
analysis
o repartition, reformat and reinstall the OS from original
media

If you want a root cause (or as close to a root cause as you'll get,
depending on the attacker's skill), engage a security firm to do
forensic analysis of the box. This is also sold as "incident
response" service. It's not cheap.

Trying to patch/remove things flagged by a commercial product is like
trying to use a bandaid to cure skin cancer, I'm afraid. You have no
way of knowing you got everything.

Best Regards,
--
Todd H.
http://www.toddh.net/
.



Relevant Pages

  • Re: DNS Root Hints / NSLookup
    ... > W2K3 Root Domain Controller is using ICS with NAT, ... > therefore two network cards are present. ... > server when connected to the other network. ...
    (microsoft.public.windows.server.dns)
  • Re: Documenting a server conf
    ... Server doesn't have network connectivity and I cannot get root access. ... Look at network config, log files, GSM hardware logs, sudo config ...
    (comp.unix.admin)
  • Re: Isolation of the Root CA
    ... Best Practices for implementing Windows Server 2003 PKI: ... If you run a network that is going to have a three tier hierarchy of>Certificate Authorities with maybe six or eight issuing CA's for various>tasks that are going to issue thousands of certificates then it makes sense>to secure the CA's that only issue certificates to other CA's to minimize>the damage that can be done to the PKI. ... You would have to start with a> standalone root CA and use it to issue a certificate for an Enterprise CA ...
    (microsoft.public.win2000.security)
  • Distributed File System question -
    ... I'm going to be rolling out a Server 2003 network and I am ... attempting to get DFS working. ... child domain of the root. ...
    (microsoft.public.windows.server.general)
  • Re: Fully parallel Scheme-based language w/ evaluator
    ... Windows Server 2003 and networks in simple - and irreverent - terms. ... If networking really is a big deal, ... Concepts and Terminology in Part I, and The Design and Deployment of Network ...
    (comp.lang.misc)