Re: Windows 2000 System Hacked

From: S. Pidgorny (slavickp_at_yahoo.com)
Date: 04/27/04

  • Next message: thejd: "Re: My home page has changed to "CoolWWWSearch" variant"
    Date: Tue, 27 Apr 2004 19:24:27 +1000
    
    

    This is the result of the new exploit for the MS04-011 SSL vulnerability. It
    creates command console on 31337/TCP (same as BackOrifice).

    http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx

    and, in your case,

    http://securityadmin.info/faq.htm#hacked

    -- 
    Svyatoslav Pidgorny, MVP, MCSE
    -= F1 is the key =-
    "Bob Smith" <bob@neconsulting.net> wrote in message
    news:upjoe57KEHA.556@TK2MSFTNGP10.phx.gbl...
    > Recently we had a Windows 2000, IIS 5.0 server hacked, what was strange
    was
    > it appears to have been from the webdav vulnerability as it connected to
    the
    > port commonly used by Back Orifice, although no BO files were drop on the
    > system.
    >
    > I thought the webdav vulnerability patch was released a year ago, although
    > this system was fully patched except for the latest five patches, and IIS
    > was fully locked down. Does anyone know if without the latest patches are
    > the systems vulnerable to the webdav.
    >
    > Thanks in advance,
    > Bob Smith
    >
    >
    

  • Next message: thejd: "Re: My home page has changed to "CoolWWWSearch" variant"

    Relevant Pages

    • Re: Is MSIE dead as a browser - if Microsoft does not patch it then it is as far as I am concerned!
      ... M$ issuing patches "PDQ" is ... >> files served by the web server. ... this vulnerability ... the installed patch ...
      (microsoft.public.security.virus)
    • Re: Bad sectors... how bad?
      ... > Dude, linux is free, if MS want's to start giving away their OS's I'll ... >>> and the $100 upgrade is that the upgrade looks for previous installs. ... > online to fully update all the patches. ... >> So when a vulnerability is found you want to remain vulnerable for 6 ...
      (alt.comp.hardware.pc-homebuilt)
    • Re: Patch for CVE-2004-1334 ???
      ... default builds of Linux kernels with the Openwall patch applied since ... distros should be releasing their updates ... The vulnerability allows local users to gain root ... >> the kernel security patches ...
      (Linux-Kernel)
    • Re: Bad sectors... how bad?
      ... > complexity contains bugs and software written to fix bugs will contain ... >> and the $100 upgrade is that the upgrade looks for previous installs. ... online to fully update all the patches. ... > So when a vulnerability is found you want to remain vulnerable for 6 ...
      (alt.comp.hardware.pc-homebuilt)
    • Re: how long it took MS to come out with patch
      ... security does not look like the only argument for running Apache ... proxies in front of IIS. ... suppose there was a security vulnerability in IIS. ... you care about rapid availability of patches, ...
      (microsoft.public.inetserver.iis.security)