Re: windows 2000 professional hacked with Serv-U FTP Server

From: Tony (tony.wong@sbcglobal.net)
Date: 11/27/02


From: "Tony" <tony.wong@sbcglobal.net>
Date: Wed, 27 Nov 2002 08:12:36 GMT

Hmm, I have to check. What are these?
"frank" <fbedolla@cotopaxi.com.mx> wrote in message
news:#Y5SarVlCHA.1748@tkmsftngp07...
> just one question
> did you have os2ss.exe and os2svr.exe running in your task manager?
>
> --
>
> Regards
>
> Francisco Bedolla Ramirez
> (Work)
> Mexico DF
> W2K AS SP3
> "Tony" <tony.wong@sbcglobal.net> escribió en el mensaje
> news:y1CE9.298$hh1.21681209@newssvr21.news.prodigy.com...
> > ports 137-139 are blocked at the border router. It was running sp2.
Norton
> > Antivirus Corporate edition was running. Administrator did have a pretty
> > strong password.
> >
> > I dont know how they uploaded this trojab and started a server Serv-U
Ftp
> > Server listening on a high port 7000 or something like that
> >
> > Also All files uploaded was hidden under "My Pictures"
> >
> > Serveral accounts were created and were in the local admin group
> >
> >
> >
> > "Jeff Cochran" <jcochran.nospam@naplesgov.com> wrote in message
> > news:3de2184f.1199174@news.easynews.com...
> > > >This machine was not running IIS. how did they get in? auditing was
> > turned
> > > >off so no security info.
> > >
> > > Is your firewall blocking ports 137-139? Are you using strong
> > > passwords? Have you *now* truned on auditing so you can see future
> > > attacks? After having reformatted and reinstalled to eliminate the
> > > trojans/back doors/etc.?
> > >
> > > Jeff
> >
> >
>
>
> ---
> Outgoing mail is certified Virus Free.
> Checked by AVG anti-virus system (http://www.grisoft.com).
> Version: 6.0.422 / Virus Database: 237 - Release Date: 20/11/2002
>
>



Relevant Pages

  • Re: Exchange - Pop 3 - SMTP
    ... Hmm hab ich noch nicht probiert, könnte ich indem Fall ja auch mal Testen, ... > Exchange CAL brauchst? ... Der mitgelieferte Pop3 Server, hmm den hab ich noch nicht probiert, wie ... Du meinst ja nicht den Pop3 Connection Manager oder? ...
    (microsoft.public.de.exchange)
  • Re: cvs-src summary for August 23-30
    ... Hmm, I have FreeBSD BETA1 laptop hooked to my FreeBSD-BETA2desktop ... as the server and they're both working very nicely. ... changelog entry "Fixes for FreeBSD." ...
    (freebsd-current)
  • Re: dawkins, hitchens, atheism and christianity
    ... Hmm, posted this before and it never showed up. ... I think my ISP's news ... server is having issues. ... de Paiwas, Nicaragua. ...
    (talk.origins)
  • Re: How to get the contnet of clipboard
    ... > Hmm, ... Nah, you weren't "harsh". ... There's a server involved. ... >> which captures client data, in sync with the current ASP.NET context, ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: XP Pro cant join W2K domain, or get to internet
    ... enabled NetBIOS, it joined fine. ... other thing I tried was using the DNS numbers from the ISP, ... Date and time match the server within about 1 minute now. ... HMM, that looks like it wasn't set up correctly. ...
    (microsoft.public.windows.server.general)

Loading