Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar Mark Forums Read
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 10-15-2003, 02:05 PM   #1
lvadavid
Registered User
 
Join Date: Oct 2003
Posts: 21
hackers using our server to share movies and games?

We run our servers on Windows NT 4.0 (yes I know, it's time to upgrade or leave Windows).

Recently it appears someone from Europe has hacked into our servers and uploaded movie and games files to share with others. ALso, they deleted a number of our Weblogs.

Anyone else experience this? Any tips for preventing it? Can they do serious harm to our servers if they want to?

Thanks.

David
lvadavid is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-15-2003, 02:09 PM   #2
XxXotic
Confirmed User
 
Join Date: Jun 2002
Location: Da Swamps
Posts: 8,500
Quote:
Originally posted by lvadavid
We run our servers on Windows NT 4.0 (yes I know, it's time to upgrade or leave Windows).

Recently it appears someone from Europe has hacked into our servers and uploaded movie and games files to share with others. ALso, they deleted a number of our Weblogs.

Anyone else experience this? Any tips for preventing it? Can they do serious harm to our servers if they want to?

Thanks.

David
i think you answered your own question when you said they "deleted weblogs" if they can delete shit, obviously they can fuck things up.

recommendation - leave windows, though that won't be 100% effective, it'll be a hell of a lot more secure not running NT
__________________
Oxeo - Serious Hosting For Serious Webmasters. iCQ:135.887013
XxXotic is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-15-2003, 02:09 PM   #3
- Jesus Christ -
Confirmed User
 
Industry Role:
Join Date: Mar 2003
Location: ::::::::::::: :::::::::::||::::::::::: :::::::::::||::::::::::: :::::::::::||::::::::::: :::::::::::||::::::::::: :::::::::::||::::::::::: ::::::||||||||||||:::::: :::::::::::||::::::::::: :::::::::::||::::::::::: ::::::::::::::::::::::::
Posts: 7,197
They can do anything they want on your servers. They have full control.

Change all your passwords after you patch windows.
Still might not get rid of them.
__________________

Amen
- Jesus Christ - is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-15-2003, 02:10 PM   #4
BoNgHiTtA
Confirmed User
 
Join Date: May 2003
Location: Seattle
Posts: 2,176
Tip #1

Hire someone who knows that the fuck there doing on your systems.
Sounds like some script kiddie just ownd ur box and is using it to distro Warez from.

Tip #2

Move to another OS. Enough said
BoNgHiTtA is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-15-2003, 02:17 PM   #5
lvadavid
Registered User
 
Join Date: Oct 2003
Posts: 21
Does installing ZoneAlarm help so I can monitor outbound data, and programs requesting Internet access?

I just began at a new company that has been running these servers and uses Cold Fusion for most web pages.

I am trying to switch to a FreeBSD, MySQL, PHP, Apache solution, but it looks like it'll takes a few months rather than a few weeks. We have nearly 1000 pages.

In the meantime, I'd like to be as secure as possible and not lose everything.

(As you can see, I do marketing and sales, and am not an expert on the technical side of things, but I do understand most of what I'm told when it comes to this stuff.)

David
lvadavid is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-15-2003, 03:45 PM   #6
Fuckin Bill
Confirmed User
 
Join Date: Feb 2003
Posts: 1,020
If you've already got people in your box, installing security software now isn't going to do shit.

You need to hire a good server admin and get microsoft off that system as soon as possible.
Fuckin Bill is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-15-2003, 03:49 PM   #7
buddyjuf
Guest
 
Posts: n/a
I used to be a hacker and as a hacker I had ways to secure the exploits so other ppl couldnt hack it no more

my advice is to get patched up against IIS, SQL, Netbios and NTPass. I remember those to be the most used methods back in the day

hope this helps!
  Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-15-2003, 03:50 PM   #8
cluck
Confirmed User
 
Join Date: Dec 2002
Location: New Jersey
Posts: 5,248
You have no idea how they got in? You could probably just install a patch for the time being. It was probably just some stupid unicode bug, I used to scan for those all the time and we'd packet people from about 10,000 compromised IIS servers. It wouldn't be hard for them to start an FTP service from their browser with one of these.
__________________
icq 279990726
www.mcdonalds.com <- great money making opportunity
cluck is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-15-2003, 04:08 PM   #9
lvadavid
Registered User
 
Join Date: Oct 2003
Posts: 21
Quote:
Originally posted by cluck
You have no idea how they got in? You could probably just install a patch for the time being. It was probably just some stupid unicode bug, I used to scan for those all the time and we'd packet people from about 10,000 compromised IIS servers. It wouldn't be hard for them to start an FTP service from their browser with one of these.
This sounds exactly like what one of my IT people said. He did say something about "unicode." He also said something about using "TFTP" or something like that.

We did try to install a patch, but the computer will not allow us to install the patch now. It appears whatever they did to our machine, they made it so that we can not install the patch from MS.

Time to format?

You all are being super-helpful. Thanks!

David
lvadavid is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-15-2003, 04:34 PM   #10
pat
Confirmed User
 
Join Date: Jan 2002
Location: UK
Posts: 157
Quote:
Originally posted by lvadavid
We run our servers on Windows NT 4.0 (yes I know, it's time to upgrade or leave Windows).

Recently it appears someone from Europe has hacked into our servers and uploaded movie and games files to share with others. ALso, they deleted a number of our Weblogs.

Anyone else experience this? Any tips for preventing it? Can they do serious harm to our servers if they want to?

Thanks.

David
Turn off "Allow anonymous connections" in the Security Accounts tab of your FTP site in IIS. The same thing happened to me - they left music/porn/games in directories which are hard to delete (i.e. system names and special characters). It's a stupid thing but with the wrong permissions and the fact IIS has this option set by default, it's easy for people to gain access and create these things. Found this URL which may help if you have loads of 'tagged' dirs on your root folder...

HTH.
pat is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-15-2003, 06:19 PM   #11
Fuckin Bill
Confirmed User
 
Join Date: Feb 2003
Posts: 1,020
If you don't know how they got in, the safest thing to do is format the drive and re-install everything, and install all patches before you put it back online. Once someone has been in the box they could have installed anything. You can run any patch you want now and they could have backdoors already installed that will let them back in.

You're playing with fire. If they've gotten into that machine, every other machine it's connected to on your network is also at risk. The longer you leave it online, with nobody knowing who's in there or how they got in there, the more chance you have of something going horribly wrong.

If they're only running warez through it, you're lucky. Have you ever seen how fast compromised systems spread on IRC? You've already said they have the power to delete system files. If they have access to that, they most likely have access to everything on the system.
Fuckin Bill is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-15-2003, 08:57 PM   #12
lvadavid
Registered User
 
Join Date: Oct 2003
Posts: 21
Thanks for all the responses.

After searching, I found a link that describes an exact description of what has happened... including the exact reference to "Inetpub" which was a folder created on our drive.

http://www.sans.org/y2k/unicode.htm

Anyone else seen this one?

David

Last edited by lvadavid; 10-15-2003 at 09:00 PM..
lvadavid is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks
Thread Tools



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.