Re: windows 2000 professional hacked with Serv-U FTP Server

From: Tony (tony.wong@sbcglobal.net)
Date: 11/27/02


From: "Tony" <tony.wong@sbcglobal.net>
Date: Wed, 27 Nov 2002 08:12:36 GMT

Hmm, I have to check. What are these?
"frank" <fbedolla@cotopaxi.com.mx> wrote in message
news:#Y5SarVlCHA.1748@tkmsftngp07...
> just one question
> did you have os2ss.exe and os2svr.exe running in your task manager?
>
> --
>
> Regards
>
> Francisco Bedolla Ramirez
> (Work)
> Mexico DF
> W2K AS SP3
> "Tony" <tony.wong@sbcglobal.net> escribió en el mensaje
> news:y1CE9.298$hh1.21681209@newssvr21.news.prodigy.com...
> > ports 137-139 are blocked at the border router. It was running sp2.
Norton
> > Antivirus Corporate edition was running. Administrator did have a pretty
> > strong password.
> >
> > I dont know how they uploaded this trojab and started a server Serv-U
Ftp
> > Server listening on a high port 7000 or something like that
> >
> > Also All files uploaded was hidden under "My Pictures"
> >
> > Serveral accounts were created and were in the local admin group
> >
> >
> >
> > "Jeff Cochran" <jcochran.nospam@naplesgov.com> wrote in message
> > news:3de2184f.1199174@news.easynews.com...
> > > >This machine was not running IIS. how did they get in? auditing was
> > turned
> > > >off so no security info.
> > >
> > > Is your firewall blocking ports 137-139? Are you using strong
> > > passwords? Have you *now* truned on auditing so you can see future
> > > attacks? After having reformatted and reinstalled to eliminate the
> > > trojans/back doors/etc.?
> > >
> > > Jeff
> >
> >
>
>
> ---
> Outgoing mail is certified Virus Free.
> Checked by AVG anti-virus system (http://www.grisoft.com).
> Version: 6.0.422 / Virus Database: 237 - Release Date: 20/11/2002
>
>



Relevant Pages

  • Re: Exchange - Pop 3 - SMTP
    ... Hmm hab ich noch nicht probiert, könnte ich indem Fall ja auch mal Testen, ... > Exchange CAL brauchst? ... Der mitgelieferte Pop3 Server, hmm den hab ich noch nicht probiert, wie ... Du meinst ja nicht den Pop3 Connection Manager oder? ...
    (microsoft.public.de.exchange)
  • Re: cvs-src summary for August 23-30
    ... Hmm, I have FreeBSD BETA1 laptop hooked to my FreeBSD-BETA2desktop ... as the server and they're both working very nicely. ... changelog entry "Fixes for FreeBSD." ...
    (freebsd-current)
  • Re: How to get the contnet of clipboard
    ... > Hmm, ... Nah, you weren't "harsh". ... There's a server involved. ... >> which captures client data, in sync with the current ASP.NET context, ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: XP Pro cant join W2K domain, or get to internet
    ... enabled NetBIOS, it joined fine. ... other thing I tried was using the DNS numbers from the ISP, ... Date and time match the server within about 1 minute now. ... HMM, that looks like it wasn't set up correctly. ...
    (microsoft.public.windows.server.general)
  • Re: Newbie: Tutorial
    ... > über einen MS2000 Server an das Internet anbinden. ... Hmm ich kann dir zumindest empfehlen, dich in die diverse Literatur bspw. ... Für die praktischen Problemlösungen und Aufgaben die du dann noch bekommen ...
    (microsoft.public.de.german.win2000.active_directory)