Re: Hidden services/processes in Win2k server

From: David Wang [Msft] (someone@online.microsoft.com)
Date: 02/14/03


From: "David Wang [Msft]" <someone@online.microsoft.com>
Date: Fri, 14 Feb 2003 00:24:17 -0800


Reinstall the machine and lock it down. The current install has been
compromised. You have no idea what backdoors may be running on it, when it
is running, what process it is named, etc, and there are no tools that can
tell you "your system is clean" next to a format and re-install. Any tool
that claims to be able to "clean up a machine that has been compromised" is
snake-oil.

For example, I can rename my backdoor program to be "svchost.exe", which is
a legitimate process to be running on Windows Servers. I can further
disguise that program by putting it in System32 directory, renaming my DLLs
to be similar to system ones (or sound like system ones), and no tool will
ever safely detect this -- because if they are wrong, they just screwed your
system.

--
//David
This posting is provided "AS IS" with no warranties, and confers no rights.
//
"Finn" <finnurt@telia.com> wrote in message
news:7fa5cf1a.0302120527.3052e012@posting.google.com...
Hi!
We have recently had some problems with people running telnet server,
ftp server (mainly for software/game distribution) on our web server.
I have found around 50 files or so like winshell, vhost, ftp software
etc, originating from them (almost all of them hidden in
/winnt/system32 and its subdirectories).
All the game/software traffic went to and from the System volume
information folder, which was of course hidden and inaccessible even
to the administrator, except if I connected through radmin/file
transfer. (Tip for those who suddenly lost 35+ Gb of hard disk space
and wonder where it went...)
Anyway, I am about to clean up the mess, and I wonder if you know any
software or commands to find out if there's additional (hidden)
services/processes running, except those displayed in Computer
management>Services and Task Manager>Processes.
PS. We're also about to install SecureIIS, does anyone have any good
or bad experiences with it?
Thanks!
Finn


Relevant Pages

  • Re: rename servers to upgrade?
    ... If you have only two DC and you decide to clean install one after another ... run DCPromo on it to remove the active directory from the server ... preferred DNS server under TCP/IP configuration. ...
    (microsoft.public.windows.server.setup)
  • Corrupt 2003 Services
    ... I'm having the strangest problem with a clean built SBS2003 server, ... I now attempt to install the IIS g-zip compression fix in ...
    (microsoft.public.windows.server.sbs)
  • Re: Domain Controller Rebuild question
    ... Symantec AV server, SMS Management point, etc. ... Orange County District Attorney ... existing down to a member server, bare metal install 2003 and then ... it back up which would give you a clean start on the ...
    (microsoft.public.windows.server.active_directory)
  • Re: Corrupt 2003 Services
    ... > I'm having the strangest problem with a clean built SBS2003 server, ... > I now attempt to install the IIS g-zip compression fix in ...
    (microsoft.public.windows.server.sbs)
  • Re: New Event Log Errors!
    ... Somehow along those lines I'd also installed the Certificate Authority ... Did you apply the last Server Pack for SBS Server? ... Please install Windows Support Tools on the win2k3 sp1 problematic ... Microsoft is providing this information only as a convenience to you: ...
    (microsoft.public.windows.server.sbs)

Quantcast