Re: Hacker



Hello,

is this server reachable through Remote Desktop or VNC ?
Did you change the admin password ?
Check that he didn't create another admin account.
Run antivirus/antipsyware (spybot for example) on the server.
Is the guest account still desactivated ?

Run MBSA against the server:
http://www.microsoft.com/downloads/details.aspx?FamilyId=4B4ABA06-B5F9-4DAD-BE9D-7B51EC2E5AC9&displaylang=en

Disable windows service like server, remote registry.

If you want to, i can run a test from home to make a checkup (mail me in private)

In doubt, you may just reinstall it from scratch.


--
Cordialement,
Mathieu CHATEAU
English blog: http://lordoftheping.blogspot.com
French blog: http://www.lotp.fr


"John Parker" <newsgroup@xxxxxxxxxxxxx> wrote in message news:uhc4v2DDIHA.5856@xxxxxxxxxxxxxxxxxxxxxxx
I need some advice regarding a 2003 web server.

We have been hacked by something called turkishhacker.mdx which installs new index.html, index.asp, index.php and default. range of same in the root directory letting the world know on the affected website it has been hacked.

This is the second time in 6 months this has happened and after the first time I made quite a few changes.

- All security updates are in place
- There is no write permissions set on root
- All site are isolated with unique user permissions
- FrontPage permissions in use

I am puzzled how this can be happeneing where there is no write permission in place. It does not affect all sites but about 60% and they are not always the same as last time.

Can anyone give me some advice?

Thanks
John Parker



.



Relevant Pages

  • Re: Permissions to see items in mailbox?
    ... >have all the permissions in the world if you also erase ... >> I have a problem with the rights of my exchange server. ... >> the admin account, ...
    (microsoft.public.exchange2000.admin)
  • Re: Public Folder Security/Sharing
    ... In Exchange System Manager on the server, can you change the owner of the ... PFto include your admin account and replicated the change down to all of ... Then you can modify the permissions and replicate again. ...
    (microsoft.public.exchange2000.active.directory.integration)
  • Cant add additional mailboxes after upgrade 5.5-2003????
    ... I just recently installed an Ex2003 server in order to migrate from 5.5. ... am the only admin in the company so I previously had permissions to open ... tried the domain admin account, the exchange admin account, my account ...
    (microsoft.public.exchange.admin)
  • RE: 403 Site gone missing!
    ... permissions and files and configurations for site access so it doesn't go ... In the browser on the server I get: 403 you do not have permission. ... -made sure the admin account to sp is the admin on the server itself. ...
    (microsoft.public.sharepoint.portalserver)
  • Re: write with cURL
    ... execute permissions. ... of potential security risks from other users on the same server. ... I made this suggestion because their web host appears to run Apache ... risk to allow Apache's group write access, since all PHP scripts ran ...
    (alt.php)