Re: Windows 2003 , MSDE 2000, Terminal Services



nick.kernick@xxxxxxxxx wrote:
My server is being hacked. User from Hong Kong [kenny] he emailed me;
Created user "asp.net" gave it admin rights, then logged on using
terminal services. I restricted TS to my IP, he came in as the
server???

Has anybody got any ideas how this can happen? Iam at a loss and
tried everything from renaming admin, firewall, disabling everything
in IIS apart from ASP.

In practical terms you only have one course of action: flatten the server and reinstall. Hopefully you took an image and can use that to quickly get up and running again. If not, as a systems administrator you should make regular imaging part of your normal routine.

As for how it happened, obviously your network and/or programs, OS are not secure. There is no way for people just reading about it on a newsgroup to know the details. Hire an outside professional to come on-site and set you up properly. This will not be someone from BigComputerStore/GeekSquad but a computer professional with skills in setting up servers.

Since your server is compromised, you also need to check all workstations for infection. This is a big job but not one that you should skip.


Malke
--
Elephant Boy Computers
www.elephantboycomputers.com
"Don't Panic!"
MS-MVP Windows - Shell/User
.



Relevant Pages

  • Re: getting me ducks in a row - concepts
    ... Don't create local login accounts for users, ... > the user has local admin rights and you will want to tweak this using RegMon ... keys on the server? ...
    (microsoft.public.windows.server.sbs)
  • Re: IIS and Frontpage security
    ... The user must have FP Admin rights to the web, this is not that same as have Admin rights to the ... server via the OS. ... FrontPage Resources, WebCircle, MS KB Quick Links, etc. ... When I log in as an administrator I can edit the webpage ...
    (microsoft.public.frontpage.extensions.windowsnt)
  • Re: How do I find I am administrator?
    ... I do not have admin rights to whole server? ... > Based on the output you fell inside the 'db_owner' role in your database. ... > 3.Is package admin is different than server adminn? ...
    (microsoft.public.sqlserver.server)
  • Re: How do I find I am administrator?
    ... I do not have admin rights to whole server? ... > Based on the output you fell inside the 'db_owner' role in your database. ... > 3.Is package admin is different than server adminn? ...
    (microsoft.public.sqlserver.tools)
  • Re: How do I find I am administrator?
    ... I do not have admin rights to whole server? ... > Based on the output you fell inside the 'db_owner' role in your database. ... > 3.Is package admin is different than server adminn? ...
    (microsoft.public.sqlserver.setup)