Re: Hacked Server - Can't Delete Planted Files

From: Karl Levinson [x y] mvp (levinson_k@excite.com)
Date: 12/20/02


From: "Karl Levinson [x y] mvp" <levinson_k@excite.com>
Date: Thu, 19 Dec 2002 19:22:57 -0500


I agree. Have you taken steps to determine how the computer was
compromised? One common way is if you have Microsoft FTP service running
and the anonymous user has both read and write permissions to any one
folder. This kind of hack is not so bad. If Microsoft IIS FTP service was
not running, then the hacker was able to remotely run code and install an
FTP server software on your server, which is bad. You may want to consider
formatting and reinstalling, because you'll never be 100% sure otherwise
that you've found and removed all back doors that would allow a hacker to
re-enter your computer and trash or steal your files to punish you, whether
or not you had already closed the original hole that let him in. Also, this
person could very well have gotten the passwords from your computers, credit
card numbers, etc.

To delete the folder and read more about how this happened:

http://securityadmin.info/faq.htm#ftpfolder

[PS I doubt booting to safe mode as suggested in the other post is going to
help]

See below for info on how to look for evidence of how the hacking happened,
and then secure your computer. Start with your IIS logs, looking for
anything that has .EXE or % and that also has a code 200 or 502 in it, and
also use Vision from www.foundstone.com/knowledge and the other tools
described below:

http://securityadmin.info/faq.htm#hacked
http://securityadmin.info/faq.htm#iislogs2
http://securityadmin.info/faq.htm#iislogs
http://securityadmin.info/faq.htm#re-secure
http://securityadmin.info/faq.htm#harden

"MrMike" <mrmike@seanet.com> wrote in message
news:07a701c2a771$7bc9a1f0$d5f82ecf@TK2MSFTNGXA12...
> Windows 2000 Server running on DSL line and (yes I know)
> no firewall. Twice now I've been hacked by someone who
> plants within my web site directory in inetpub, folders
> such as com1, com1, com1, com1, and then identifys himself
> (or herself?) with the names of successive folders below
> each other such as "scaned by XXX", "Planted by XXX".
>
> I suspect I'm being relayed through since my router goes
> nuts when I'm not doing anything.
>
> I can't delete these folders or files. The Message says
> that they don't exist or can't be found.
>
> How do I delete these folders and files?
>
> Thank you All!
>
> mrmike



Relevant Pages

  • Re: unable to delete locked folders on our company ftp
    ... Stop the FTP service, delete the file you want, fix the permission problem, ... basically someone enabled FTP on our ISS server but forgot to take ... > had people uploading rubbish to it. ... > I'm unable to delete the files and folders that were uploaded. ...
    (microsoft.public.inetserver.iis.ftp)
  • Re: Sp1 and Eval SBS 2003 Unable to Install
    ... > * Use Outlook to export the contents in the public folders to .pst files ... > partition and clean install SBS 2003 server. ... > Another way is to create a local profile, ...
    (microsoft.public.windows.server.sbs)
  • Re: Sp1 and Eval SBS 2003 Unable to Install
    ... * Use Outlook to export the contents in the public folders to .pst files ... partition and clean install SBS 2003 server. ... Another way is to create a local profile, ...
    (microsoft.public.windows.server.sbs)
  • RE: Offline Address Book error on send/receive
    ... Hi Jenny...I've done this reset successfully on a test server so I will be ... The folders are system folders. ... Microsoft CSS Online Newsgroup Support ...
    (microsoft.public.windows.server.sbs)
  • Re: no remote folder in Remote Web Workplace
    ... You can check the files and folders for RWW site as follows (You can find ... no remote folder in Remote Web Workplace ... If the value of the key is '1', it reveals the server is at SP1. ...
    (microsoft.public.windows.server.sbs)