Re: Virus running through our network

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 05/18/05


Date: Wed, 18 May 2005 13:35:09 -0500


>From the description of what the Symantec technician said it sounds like the
infection relies on weak passwords and weak share permissions. Weak
passwords would be the biggest threat. Windows 2000 by default also gives
everyone full control access to a new share which then puts all your share
security on ntfs permissions. Windows 2000 also installs a number of
services by default that should be disabled such as IIS if not used.

Based on your description and what Symantec said I would do at least the
following.

Make sure your antivirus is kept up to date AND scans ALL email attachments.
Keeping current with critical updates is great but that will only help
prevent malware that attacks operating system vulnerabilities such as
blaster.

If at all possible do not allow your users to be local administrators.
Review administrator group membership on all your computers and for the
domain to make sure it is what you expect.

Use a password policy that enforces password complexity and require
passwords to be at least seven characters in length. If that is a big change
for your users be sure to educate them of changes ahead of time. You will
have to force users to change their passwords if you currently do not use
expiring passwords. User accounts can be configured to "change password at
next logon".

Run the Microsoft Baseline Security analyzer on all your computers to check
for many vulnerabilities including very weak passwords and open share
permissions. It is free and available at the link below.

http://www.microsoft.com/technet/security/tools/mbsahome.mspx

Read the free Microsoft Antivirus in Depth guide from the link below. It
explains how malwares work/propagate, how to deal with virus outbreaks, and
preventative actions for the future.

http://www.microsoft.com/technet/security/topics/serversecurity/avdind_0.mspx

Review security practices at Technet Security that apply to your network,
applications, and operating systems. --- Steve

http://www.microsoft.com/technet/security/default.mspx

"Carl Gross" <CarlGross@discussions.microsoft.com> wrote in message
news:046A3853-D89B-497F-BBB8-6CF9A2414E61@microsoft.com...
> Recently, the Backdoor.Trojan virus popped its head into our network. I
> restarted all the machines in safe mode and ran our anti-virus programs
> and
> it appeared as though it got them (even on the machines that didn't pop up
> with a virus alert).
>
> When I spoke with the Symantec technician, he said it probably got through
> the network via our network shares. He suggested that it may have broken
> through our simple passwords onto each machine. I have W2K SP4
> workstations
> that are up-to-date on their critical updates. Can the virus still run
> through with permissions like Domain Admins having full rights and Domain
> Users having R/W rights?
>



Relevant Pages

  • Re: Date filed in table
    ... You can control some deletes, etc. from paradox based on passwords and permissions you set but they can be broken and it can get complicated to manage multiple levels across multiple tables and various users, permissions and systems. ... also like a field showing the last time the table entry was edited. ...
    (comp.databases.paradox)
  • Re: Problem managing accounts in protected groups
    ... As I understand it you have a collection of users in some group which are allowed to reset passwords of domain admin accounts? ... The permissions for this group have been applied to OU B and it ... or passwords for the users in the protected groups. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Clients not able to login to Domain
    ... Passwords are supposed to remained synched between AD and Novell, ... it may be a "permissions" issue. ... >> You say Not able to login, but then your error is not able to map? ...
    (microsoft.public.windows.server.sbs)
  • Re: Closed LAN: want WORKGROUP to share w/o passwords
    ... the passwords and permissions? ... I'm lost in PERMISSIONS and PASSWORD "hell"! ... XP Pro file sharing in a workgroup doesn't use permissions ... Please post any reply as a follow-up message in the news group ...
    (microsoft.public.windowsxp.network_web)
  • Re: Delegation - Password Reset - Access Denied
    ... You attempt to see if the permissions are being applied as you expected. ... Open up a user's properties and select the security tab, click on advanced, ... those groups and reset passwords when needed. ...
    (microsoft.public.windows.server.active_directory)