Re: Hacked



Not always does someone hack using an exploit! Sometimes they crack the passwords etc... You have to consider every and any point of intrusion

--

http://www.goldwatches.com/
http://www.jewelerslounge.com/
"Newell White" <NewellWhite@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message news:D35907B2-F92A-4CBA-AF04-D3FC556D723E@xxxxxxxxxxxxxxxx
Record the modified and created dates on the installed files and their
containing folders. This will give you some clue as to the time window you
should search in the Security log using Event Viewer - should give you IP of
computer originating any login request.

What is your network topology?
Anti-virus software won't help.
Do you have hardware firewall between server and the wicked outside world?
If so, and it is configured correctly, this is most likely an inside job.
--
Newell White


"SuperSlueth" wrote:

I'm running exchange 2003 on server 2003 with all the latest patches and
fixes applied. I have the latest version of norton corperate antivirus with
all the updates.
I've done a full scan and the server is clean.
Yet every 2 or 3 days I see that a new user has been added "hello5" and
programs have been installed.
I can delete the programs and the user I've disabled remote desktop and
changed the admin password, but still this person still gets to the server.
does anyone have any idea how to find out where he comes in from and how to
block it

.



Relevant Pages

  • RE: VmWare and Pen-test Learning
    ... Setup a tftp server on your client machine. ... Use John the Ripper to crack the passwords. ... (dictionary attacks, brute force, single mode). ... Download FREE whitepaper on how a managed service can help ...
    (Pen-Test)
  • Re: Strange SSID in the air...
    ... the cable modem assigning Gateway+DNS to the Linksys router etc.)? ... to verify that DNS lookups actually point to the real web site. ... from overloading one server, while another remains under-utilized. ... dumb applications that are not very smart about encrypting passwords. ...
    (alt.internet.wireless)
  • Re: unified authentication
    ... > I have a number of FreeBSD machines. ... Each *class* of server or device gets a different root password (or ... root/enable passwords, and have a bit less worry about ex-employees. ... only sysadmins have logins on routers.) ...
    (FreeBSD-Security)
  • RE: Where are Local Passwords stored on Win2K
    ... This should restrict the likely hood of have access to multiple server if one is to get compromised. ... Where are Local Passwords stored on Win2K ... compromises within our network. ...
    (Security-Basics)
  • Re: Strange SSID in the air...
    ... the cable modem assigning Gateway+DNS to the Linksys router etc.)? ... to verify that DNS lookups actually point to the real web site. ... from overloading one server, while another remains under-utilized. ... dumb applications that are not very smart about encrypting passwords. ...
    (alt.internet.wireless)

Quantcast