Re: help:site hacked

From: Jonathan Maltz [MS-MVP] (jmaltz_at_mvps.org)
Date: 06/28/04

  • Next message: Todd: "Help with permissions to allow adding files to a directory but not modify any"
    Date: Mon, 28 Jun 2004 16:36:50 -0400
    
    

    Hi,

    Stay up to date on security and other hotfixes
    Get some sort of firewall

    That's a good start

    -- 
    --Jonathan Maltz [Microsoft MVP - Windows Server, Virtual PC]
    http://www.visualwin.com - A Windows Server 2003 visual, step-by-step
    tutorial site :-)
    http://vpc.visualwin.com - Does <insert OS name> work on VPC 2004?  Find out
    here
    Only reply by newsgroup.  I do not do technical support via email.  Any
    emails I have not authorized are deleted before I see them.
    "Hernán Castelo" <hcastelo@cedi.frba.utn.edu.ar> wrote in message
    news:%23ERCwhRXEHA.2520@TK2MSFTNGP12.phx.gbl...
    hi
    someone was hacked my site
    i have 2 servers :
    web--> IIS 5 / w2k adv Srv IIS lockdown
    sql--> SQL2k / w2k adv Srv
    i found the web srv doing "beeps"
    soon i found it serves html pages
    but don't serves asp with an error like
    "Error in the server application"
    sql srv lost sa password
    and don't recognize the local admin
    then i can't access to sql applications
    except of that,
    servers appears to work normal
    the web srv log is saying
    that attacked the iwam_
    and many "login misses" under DCOMSCM
    and then, "login hits"
    i go now to restore
    my backup and images
    but
    what can i do to prevent the next attack ?
    how can i protect better the site ?
    thanks
    -- 
    atte,
    Hernán
    

  • Next message: Todd: "Help with permissions to allow adding files to a directory but not modify any"

    Relevant Pages

    • Re: SRV RRs support in Internet Explorer?
      ... > nothing magical about SRV records. ... > reflect some explict or implicit order based on dynamic server loading and ... >> receives SRV RRs in a response to one of its A queries, ... The DNS Client works as ...
      (microsoft.public.win2000.dns)
    • Re: SRV RRs support in Internet Explorer?
      ... >> nothing magical about SRV records. ... >> reflect some explict or implicit order based on dynamic server loading ... The DNS Client works ... >>> domain, to move services from host to host with little fuss, and to ...
      (microsoft.public.win2000.dns)
    • best practices
      ... someone was hacked my site i have 2 servers: web--> IIS 5 / w2k adv Srv IIS lockdown sql--> SQL2k / w2k adv Srv i found the web srv doing "beeps" soon i found it serves html pages but don't serves asp with an error like "Error in the server application" sql srv lost sa password and don't recognize the local admin then i can't access to sql applications except of that, servers appears to work normal the web srv log is saying that attacked the iwam_ and many "login misses" under DCOMSCM and then, "login hits" i go now to restore my backup and images but what can i do to prevent the next attack? ...
      (microsoft.public.inetserver.iis.security)
    • Re: SRV RRs support in Internet Explorer?
      ... nothing magical about SRV records. ... that updates the recordon the DNS server to reflect current state of the ... > for host updates when new application ports are assigned, ... To be APSDR compatible, a DNS Client has, when it ...
      (microsoft.public.win2000.dns)
    • Unable to connect to database. Check database connection inf
      ... SharePoint Portal Srever 2003 installed on win srv 2003. ... My problem is that I went back to previuos config and now I'm ... 1.stoped services on SharePoint server. ...
      (microsoft.public.windows.server.setup)