Re: hackerZZzzzz

From: Paul Lynch (paul_lynch67_at_hotmail.com)
Date: 07/12/03


Date: 11 Jul 2003 15:42:50 -0700


Max,

They're probably doing nothing more scary than uploading files to the
wide open ftp server you are running.

The best advice I can offer is to take the server offline asap, back
up any important files you need to keep and format and re-install from
scratch.

Don't put the server back online until you have installed the latest
service pack and security patches. If you don't use the ftp service
disable it or at least disallow anonymous ftp to your server. If you
don't need the IIS services don't install them.

Start here :
http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/default.asp

Regards,

Paul Lynch
MCSE

 

"mAx" <bigblue@mailbolt.com> wrote in message news:<008801c347d9$b2228d30$a601280a@phx.gbl>...
> YIKES!!
>
> that sounds scary....
>
> zombies sounds like the term! It is as if they don't exist
> on the drive whenever I try to delete/copy/cut etc
>
> many thanks for the info on 'packet sniffers' (heard of
> them but never had the need to try them out! here's my
> chance I guess!)
>
> will see what I can find
>
> thanks again!
>
> mAx
>
> PS - it is the D:\ drive they are compromising - do you
> think best to do complete format/install to get rid of
> everything for sure?
>
> >-----Original Message-----
> >Any packet sniffer: windump, ethereal, etc. Although if
> you know the system
> >is compromised, you should take it off-line right away.
> Capturing the
> >traffic isn't going to do you any good--the systems that
> they're using to
> >transfer the files are likely compromised/zombies as well.
> >
> >"max towns" <bigblue@mailbolt.com> wrote in message
> >news:012b01c347d4$85891be0$a401280a@phx.gbl...
> >> Hello!
> >>
> >> trying to find some info on getting rid of unwanted
> >> folders created by hackers on my webserver.... they've
> >> been using it as a file transferring location (and are
> >> possibly watching me type this as I speak as I have just
> >> seen that have uploaded some terminal server setup stuff
> >> in the last five minutes! - hello if you're watching!)
> >>
> >> not that I'm paranoid or anything... but they're all
> over
> >> me!!
> >>
> >> haha
> >>
> >> what people do for a bit of fun eh...
> >>
> >> anyway - will prob just format the drive and be done but
> >> would be nice to know for future reference...
> >>
> >> (anyone know how to check where exactly the data that is
> >> reported in the status as being sent and received for
> the
> >> network/internet connection - is going to?)
> >>
> >> MAny many thanks for any help :)
> >>
> >> mAx
> >
> >
> >.
> >



Relevant Pages

  • RE: FTP Problem after applying MS patches
    ... Thank you for posting to the SBS Newsgroup. ... Server and the active FTP does not work. ... Based on KB 898060, if we install MS05-019, we should install the newest ...
    (microsoft.public.windows.server.sbs)
  • Re: Sysinstall FTP from LAN - not working
    ... > I am trying to install 5.2.1 from an iMac running OSX with an FTP ... > connecting to the FTP server on the iMac. ... > I set up the network information automatically with the DHCP selection ...
    (freebsd-questions)
  • FTP Client problems behind SBS2003 Server
    ... >I have an SBS2003 install and on some of the clinet ... The software developer says they wrote the FTP ... >wizard as I do not wish to run an FTP server on the SBS ... >data connection to client" from within QFTP. ...
    (microsoft.public.windows.server.sbs)
  • Help with IPFW + NATD + Passive FTP
    ... passive FTP connections through IPFW with NATD enabled. ... $cmd 005 allow all from any to any via dc0 ... # Interface facing Public internet ... # Allow out access to my ISP's Domain name server. ...
    (freebsd-questions)
  • RE: Client Computers cannot upload or download from Remote FTP ser
    ... SBS External NIC - Cannot FTP From this server ... SBS Internal NIC ... FTP server is Checked in Routing and Remote Access - Internet Connection - ...
    (microsoft.public.windows.server.sbs)