help:site hacked

From: Hernán Castelo (hcastelo_at_cedi.frba.utn.edu.ar)
Date: 06/28/04

  • Next message: RG: "File Download"
    Date: Mon, 28 Jun 2004 11:04:50 -0300
    
    

    hi
    someone was hacked my site
    i have 2 servers :
    web--> IIS 5 / w2k adv Srv IIS lockdown
    sql--> SQL2k / w2k adv Srv

    i found the web srv doing "beeps"
    soon i found it serves html pages
    but don't serves asp with an error like
    "Error in the server application"

    sql srv lost sa password
    and don't recognize the local admin
    then i can't access to sql applications

    except of that,
    servers appears to work normal

    the web srv log is saying
    that attacked the iwam_
    and many "login misses" under DCOMSCM
    and then, "login hits"

    i go now to restore
    my backup and images
    but
    what can i do to prevent the next attack ?
    how can i protect better the site ?

    thanks

    -- 
    atte,
    Hernán
    

  • Next message: RG: "File Download"

    Relevant Pages

    • help: site hacked
      ... web--> IIS 5 / w2k adv Srv IIS lockdown ... sql--> SQL2k / w2k adv Srv ... servers appears to work normal ...
      (microsoft.public.security)
    • help: site hacked
      ... web--> IIS 5 / w2k adv Srv IIS lockdown ... sql--> SQL2k / w2k adv Srv ... servers appears to work normal ...
      (microsoft.public.inetserver.iis.security)
    • help: sql hacked
      ... web--> IIS 5 / w2k adv Srv IIS lockdown ... sql--> SQL2k / w2k adv Srv ... servers appears to work normal ...
      (microsoft.public.sqlserver.security)
    • Re: Exchange 2003 GAL replication to Exchange 5.5 Site
      ... > I have a Win2003/Exch2003 Srv. ... > User/Mailbox on my Win2003/Exch2003 Srv the GAL on my Exch ... > Messages/Public folder updates are transferring between ... > the Exch2003 and Exch 5.5 servers OK. ...
      (microsoft.public.exchange.connectivity)