Re: windows 2000 professional hacked with Serv-U FTP Server

From: Tony (tony.wong@sbcglobal.net)
Date: 11/25/02


From: "Tony" <tony.wong@sbcglobal.net>
Date: Mon, 25 Nov 2002 05:41:29 GMT


This machine was not running IIS. how did they get in? auditing was turned
off so no security info.
"Karl Levinson [x y] mvp" <jamescagney90210@excite.com> wrote in message
news:u#cXGL9kCHA.2752@tkmsftngp09...
>
> "Tony" <tony.wong@sbcglobal.net> wrote in message
> news:KiZD9.3089$Wq7.231812136@newssvr21.news.prodigy.com...
> > Someone hacked into my windows 2000 machine running sp2 and installed
> Serv-U
> > FTP server and was uploading movies files to this box. This box was
> running
> > sp2. Looking in the local users, a bunch of users were created and
belong
> to
> > the local adminitrator group. File and print sharing, was enabled on
this
> > box.
> >
> > How did hacked get into the machine and installed Serv-U ftp server?
>
> Start by checking your IIS web logs. Look for anything that says .EXE or
%
> and that also has a 200 or 502 in it. Frequently, an unpatched
> vulnerability in the IIS web service on your machine will let a hacker
> remotely send commands to your computer by sending URLs to your IIS web
> server service.
>
> More information:
>
> http://securityadmin.info/faq.htm#hacked
> http://securityadmin.info/faq.htm#iislogs2
> http://securityadmin.info/faq.htm#iislogs
>
> > How do I prevent this from happening?
>
> Secure your machine properly. [But first, determine how the hack occurred
> and whether other machines are infected, using the instructions above.
> Then, consider formatting and reinstalling Windows and all other software
> from scratch. The reason for this is that it's hard to tell what other
back
> doors might have been added to your machine or passwords or credit card
> numbers gotten from your machine.]
>
> It sounds like you're not running a firewall or antivirus, for one, are
> missing Microsoft patches, and haven't used one or more hardening
checklist
> documents to remove the vulnerabilities in the default install of Windows.
> More info:
>
> http://securityadmin.info/faq.htm#re-secure
> http://securityadmin.info/faq.htm#harden
> http://securityadmin.info/faq.htm#firewall
> http://securityadmin.info/faq.htm#virus
>
>
>
>



Relevant Pages

  • RE: FTP and IIS HACK!!!
    ... Disable posix install into a new dir, update machine with newest IIS rollup ... | Content-Class: urn:content-classes:message ... | Sender: "David Little" ... | FTP server is stoppped and a version of serv-u is started ...
    (microsoft.public.inetserver.iis.security)
  • Re: XP Home file transfer to and from an old Mac computer?
    ... A Mac will work. ... IIS is needed to make the FTP server. ... The best live web video on the internet http://www.seedsv.com/webdemo.htm ...
    (microsoft.public.windowsxp.general)
  • Re: I_USR requires Logon type 3 - Help!
    ... On IIS v5.1 (Windows XP). ... Locally" if you want that account to be impersonated by the FTP Server. ... When IUSR tries to logon to the FTP server, ...
    (microsoft.public.inetserver.iis.security)
  • Re: compare iis-ftp and serv-u.
    ... if some NAT manufacturer wants to give an special treatment to the body ... Then, the FTP server ... I have no doubt that a Win2003 is a great product (including IIS). ... > passive port range setting that you talk of is already available in the IIS ...
    (microsoft.public.inetserver.iis.ftp)
  • Re: Error while creating virt. dir.
    ... > i was using the ftp server only by my own, ... > i was never creating virt. ... dir. in IIS 6 / FTP am getting an error ... Have a normal manual access to the folder ...
    (microsoft.public.inetserver.iis.ftp)