Re: Unknown BackDoor/Trojan

From: Alun Jones (alun@texis.com)
Date: 12/24/02


From: alun@texis.com (Alun Jones)
Date: Tue, 24 Dec 2002 14:52:40 GMT

In article <e2L8iAtqCHA.2496@TK2MSFTNGP12>, "x y" <levinson_k@excite.com>
wrote:
>Yes, this is a fairly common event where the Serv-U FTP server was installed
>on your server due to some vulnerability that has not been patched on it.

It would be rather churlish of me, as Serv-U is one of my competitors, to
suggest that you could adjust a virus scanner's definitions to block the
running of Serv-U, since it is a valid application, but if you do find
repeated incursions and you can't plug the holes that they come in through,
such an alteration might be warranted.

In general, though, the best thing to do would be to completely lock down your
firewall, so that even if the hacker has a listening server installed on your
system, he can't connect to it.

Alun.
~~~~

[Please don't email posters, if a Usenet response is appropriate.]

-- 
Texas Imperial Software   | Try WFTPD, the Windows FTP Server. Find us at
1602 Harvest Moon Place   | http://www.wftpd.com or email alun@texis.com
Cedar Park TX 78613-1419  | VISA/MC accepted.  NT-based sites, be sure to
Fax/Voice +1(512)258-9858 | read details of WFTPD Pro for XP/2000/NT.


Relevant Pages

  • Re: Ftp Security Help!!!!!!!!
    ... You will find it much easier to have a secure and trivially configurable ... FTP server if you try Serv-U. ... Per the FCA, this address may not be added to any commercial mail list ...
    (microsoft.public.win2000.security)
  • IIS and FTP HACK!!!
    ... I am running IIS on win2k server. ... FTP server is stoppped and a version of serv-u is started ... my FTP server had its port ...
    (microsoft.public.security.virus)
  • FTP and IIS HACK!!!
    ... I am running IIS on win2k server. ... FTP server is stoppped and a version of serv-u is started ... my FTP server had its port ...
    (microsoft.public.inetserver.iis.security)
  • Re: FTP and SSL
    ... seem to have any FTP servers available. ... Serv-U, you'll want http://www.serv-u.com, or the parent site, ... same thing we support in WFTPD Pro - which is currently termed "Securing FTP ... Texas Imperial Software | Try WFTPD, the Windows FTP Server. ...
    (microsoft.public.inetserver.iis.security)
  • cuteftp pro client unable to login serv-u server
    ... i use cuteftp pro, and after install sp2, i can't login my ftp server which ... run serv-u. ... i have opend the port 21. ...
    (microsoft.public.windowsxp.work_remotely)

Quantcast