IIS
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationIIS

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old January 30th, 2006, 11:36 AM
pette.n's Avatar
pette.n pette.n is offline
Loser
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Oct 2004
Posts: 398 pette.n User rank is Corporal (100 - 500 Reputation Level)pette.n User rank is Corporal (100 - 500 Reputation Level)pette.n User rank is Corporal (100 - 500 Reputation Level)pette.n User rank is Corporal (100 - 500 Reputation Level) 
Time spent in forums: 5 Days 10 h 21 m 2 sec
Reputation Power: 5
Thumbs up Attacing to server

hi..
someone attacts to my server!

he can log-in without knowing administrator password...

I see he create users in users and groups..

how can it be blocked?

I see the following in events

Quote:
Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Logon account: usernameHeCreated
Source Workstation: myservername
Error Code: 0x0


For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.


I disabled The Accounts: Limit
local account use of blank passwords to console logon only


can he still log in my server?

Reply With Quote
  #2  
Old January 30th, 2006, 04:22 PM
SimonGreenhill's Avatar
SimonGreenhill SimonGreenhill is offline
(retired)
Dev Shed God 11th Plane (10000 - 10499 posts)
 
Join Date: Dec 2003
Location: The Laboratory
Posts: 10,101 SimonGreenhill User rank is General 5th Grade (Above 100000 Reputation Level)SimonGreenhill User rank is General 5th Grade (Above 100000 Reputation Level)SimonGreenhill User rank is General 5th Grade (Above 100000 Reputation Level)SimonGreenhill User rank is General 5th Grade (Above 100000 Reputation Level)SimonGreenhill User rank is General 5th Grade (Above 100000 Reputation Level)SimonGreenhill User rank is General 5th Grade (Above 100000 Reputation Level)SimonGreenhill User rank is General 5th Grade (Above 100000 Reputation Level)SimonGreenhill User rank is General 5th Grade (Above 100000 Reputation Level)SimonGreenhill User rank is General 5th Grade (Above 100000 Reputation Level)SimonGreenhill User rank is General 5th Grade (Above 100000 Reputation Level)SimonGreenhill User rank is General 5th Grade (Above 100000 Reputation Level)SimonGreenhill User rank is General 5th Grade (Above 100000 Reputation Level)SimonGreenhill User rank is General 5th Grade (Above 100000 Reputation Level)SimonGreenhill User rank is General 5th Grade (Above 100000 Reputation Level)SimonGreenhill User rank is General 5th Grade (Above 100000 Reputation Level)SimonGreenhill User rank is General 5th Grade (Above 100000 Reputation Level)  Folding Points: 4925 Folding Title: Novice Folder
Time spent in forums: 3 Months 3 Weeks 5 h 49 m 4 sec
Reputation Power: 1331
Facebook
Moved to IIS forum.

--Simon

Reply With Quote
  #3  
Old January 30th, 2006, 05:25 PM
pette.n's Avatar
pette.n pette.n is offline
Loser
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Oct 2004
Posts: 398 pette.n User rank is Corporal (100 - 500 Reputation Level)pette.n User rank is Corporal (100 - 500 Reputation Level)pette.n User rank is Corporal (100 - 500 Reputation Level)pette.n User rank is Corporal (100 - 500 Reputation Level) 
Time spent in forums: 5 Days 10 h 21 m 2 sec
Reputation Power: 5
Quote:
Originally Posted by SimonGreenhill
Moved to IIS forum.

--Simon


this is not about IIS ?

Reply With Quote
  #4  
Old January 30th, 2006, 05:39 PM
SimonGreenhill's Avatar
SimonGreenhill SimonGreenhill is offline
(retired)
Dev Shed God 11th Plane (10000 - 10499 posts)
 
Join Date: Dec 2003
Location: The Laboratory
Posts: 10,101 SimonGreenhill User rank is General 5th Grade (Above 100000 Reputation Level)SimonGreenhill User rank is General 5th Grade (Above 100000 Reputation Level)SimonGreenhill User rank is General 5th Grade (Above 100000 Reputation Level)SimonGreenhill User rank is General 5th Grade (Above 100000 Reputation Level)SimonGreenhill User rank is General 5th Grade (Above 100000 Reputation Level)SimonGreenhill User rank is General 5th Grade (Above 100000 Reputation Level)SimonGreenhill User rank is General 5th Grade (Above 100000 Reputation Level)SimonGreenhill User rank is General 5th Grade (Above 100000 Reputation Level)SimonGreenhill User rank is General 5th Grade (Above 100000 Reputation Level)SimonGreenhill User rank is General 5th Grade (Above 100000 Reputation Level)SimonGreenhill User rank is General 5th Grade (Above 100000 Reputation Level)SimonGreenhill User rank is General 5th Grade (Above 100000 Reputation Level)SimonGreenhill User rank is General 5th Grade (Above 100000 Reputation Level)SimonGreenhill User rank is General 5th Grade (Above 100000 Reputation Level)SimonGreenhill User rank is General 5th Grade (Above 100000 Reputation Level)SimonGreenhill User rank is General 5th Grade (Above 100000 Reputation Level)  Folding Points: 4925 Folding Title: Novice Folder
Time spent in forums: 3 Months 3 Weeks 5 h 49 m 4 sec
Reputation Power: 1331
Facebook
Sorry, I thought it was a IIS problem. Is this attack coming in via your webserver? or directly to the server? What is the operating system and webserver? any other info?

--Simon

Reply With Quote
  #5  
Old January 30th, 2006, 10:23 PM
Doug G Doug G is offline
Grumpier Old Moderator
Dev Shed God 12th Plane (10500 - 10999 posts)
 
Join Date: Jun 2003
Posts: 10,996 Doug G User rank is Major General (70000 - 90000 Reputation Level)Doug G User rank is Major General (70000 - 90000 Reputation Level)Doug G User rank is Major General (70000 - 90000 Reputation Level)Doug G User rank is Major General (70000 - 90000 Reputation Level)Doug G User rank is Major General (70000 - 90000 Reputation Level)Doug G User rank is Major General (70000 - 90000 Reputation Level)Doug G User rank is Major General (70000 - 90000 Reputation Level)Doug G User rank is Major General (70000 - 90000 Reputation Level)Doug G User rank is Major General (70000 - 90000 Reputation Level)Doug G User rank is Major General (70000 - 90000 Reputation Level)Doug G User rank is Major General (70000 - 90000 Reputation Level)Doug G User rank is Major General (70000 - 90000 Reputation Level)Doug G User rank is Major General (70000 - 90000 Reputation Level)Doug G User rank is Major General (70000 - 90000 Reputation Level) 
Time spent in forums: 1 Month 1 Day 20 h 9 m 41 sec
Reputation Power: 814
There are lots of exploits that may have happened. Generally if you got hacked you

a) haven't kept your server windows updates up to date
b) you don't have a firewall or it's not configured properly,
c) you don't have some form of antivirus and spyware blocking software,
d) you use the web server as a workstation and you did something that put bad stuff in your server,
e) you have allowed some untrustworthy person physical access to your server

a or b are likeliest. If you don't close IIS holes as soon as they are discovered and patches are available, it doesn't take long for some zombie computer to find yours and hack it.
__________________
======
Doug G
======
I didn't attend the funeral, but I sent a nice letter saying I approved
of it. --Mark Twain

Reply With Quote
  #6  
Old January 31st, 2006, 04:26 AM
pette.n's Avatar
pette.n pette.n is offline
Loser
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Oct 2004
Posts: 398 pette.n User rank is Corporal (100 - 500 Reputation Level)pette.n User rank is Corporal (100 - 500 Reputation Level)pette.n User rank is Corporal (100 - 500 Reputation Level)pette.n User rank is Corporal (100 - 500 Reputation Level) 
Time spent in forums: 5 Days 10 h 21 m 2 sec
Reputation Power: 5
the only user who can access to server (remote connection) is administrator.

no user can access to server
(I disabled "remote controll" all users without administrator)

there is no third party isapi,dll that is installed IIS.

I mean there are some holes on my server (w2k3).
and someone is using them to access my server.

he can log-in my server and can use my server he can install some applications to my server and he unistalled the antivirus that I used.. (NOD32)

connections are limited to server
only 2 users access to the server at the sametime
If I connect to server for 2 account , can he still access?

Reply With Quote
  #7  
Old January 31st, 2006, 04:30 AM
pette.n's Avatar
pette.n pette.n is offline
Loser
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Oct 2004
Posts: 398 pette.n User rank is Corporal (100 - 500 Reputation Level)pette.n User rank is Corporal (100 - 500 Reputation Level)pette.n User rank is Corporal (100 - 500 Reputation Level)pette.n User rank is Corporal (100 - 500 Reputation Level) 
Time spent in forums: 5 Days 10 h 21 m 2 sec
Reputation Power: 5
Quote:
Originally Posted by SimonGreenhill
Sorry, I thought it was a IIS problem. Is this attack coming in via your webserver? or directly to the server? What is the operating system and webserver? any other info?

--Simon


I didn't see your message sorry

OS w2k3 standard edition SP1
all updates are okay.. auto update is on

IIS 6.0

there is only one user who can access to server as remote control

but someone can create any user he want .
the users he created has administrator permissions

I have NOD32

my server are behind of firewall
there isnt local firewall

it is in datacenter (FDC)

what is your suggestions?

thank you.

Reply With Quote
  #8  
Old January 31st, 2006, 05:08 PM
Doug G Doug G is offline
Grumpier Old Moderator
Dev Shed God 12th Plane (10500 - 10999 posts)
 
Join Date: Jun 2003
Posts: 10,996 Doug G User rank is Major General (70000 - 90000 Reputation Level)Doug G User rank is Major General (70000 - 90000 Reputation Level)Doug G User rank is Major General (70000 - 90000 Reputation Level)Doug G User rank is Major General (70000 - 90000 Reputation Level)Doug G User rank is Major General (70000 - 90000 Reputation Level)Doug G User rank is Major General (70000 - 90000 Reputation Level)Doug G User rank is Major General (70000 - 90000 Reputation Level)Doug G User rank is Major General (70000 - 90000 Reputation Level)Doug G User rank is Major General (70000 - 90000 Reputation Level)Doug G User rank is Major General (70000 - 90000 Reputation Level)Doug G User rank is Major General (70000 - 90000 Reputation Level)Doug G User rank is Major General (70000 - 90000 Reputation Level)Doug G User rank is Major General (70000 - 90000 Reputation Level)Doug G User rank is Major General (70000 - 90000 Reputation Level) 
Time spent in forums: 1 Month 1 Day 20 h 9 m 41 sec
Reputation Power: 814
If you get no more help here in the IIS forum, try rephrasing your question and re-ask it in the windows forum, making it clear you're looking for windows help. If you haven't make sure you run a complete antivirus/spyware scan.

You could always backup your data, then reformat and reinstall the server OS making sure all potential holes are plugged before you put it back in service.

Reply With Quote
  #9  
Old February 3rd, 2006, 01:03 PM
juniperr juniperr is offline
network dude
Dev Shed Intermediate (1500 - 1999 posts)
 
Join Date: Dec 2003
Posts: 1,679 juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level) 
Time spent in forums: 1 Week 6 Days 21 h 55 m 2 sec
Reputation Power: 85
Unless you opened a port in the firewall to allow access via remote desktop I highly dought this is how they are getting in. Most likely they exploited IIS or your web site code and dropped a backdoor app on your server usualy they drop something in that makes a conection to IRC server this way it bypasses the firewall as the server made the connection out. If you have little experience in this then blow away the server and rebuild make sure you fully patch it before putting back online, as well check your code for php or other exploits that may allow them to upload a program or run scripts. just my opinion. (big problem is rootkits as there is no 100% way to detect these)

Last edited by juniperr : February 3rd, 2006 at 01:09 PM.

Reply With Quote
  #10  
Old February 4th, 2006, 06:26 AM
pette.n's Avatar
pette.n pette.n is offline
Loser
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Oct 2004
Posts: 398 pette.n User rank is Corporal (100 - 500 Reputation Level)pette.n User rank is Corporal (100 - 500 Reputation Level)pette.n User rank is Corporal (100 - 500 Reputation Level)pette.n User rank is Corporal (100 - 500 Reputation Level) 
Time spent in forums: 5 Days 10 h 21 m 2 sec
Reputation Power: 5
there are more than 100 sites on IIS..
how can I know which site exploits to my server?

firewall is not local
my server is in datacenter, datacenter has a firewall system..

And he can still create users he wants
but he can't login to my server..

because I connected to server with 2 accounts..
more than 2 connections are not allowed..

help me pls

( scanned server with spyware and antivirus)

Reply With Quote
  #11  
Old February 4th, 2006, 07:06 AM
pette.n's Avatar
pette.n pette.n is offline
Loser
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Oct 2004
Posts: 398 pette.n User rank is Corporal (100 - 500 Reputation Level)pette.n User rank is Corporal (100 - 500 Reputation Level)pette.n User rank is Corporal (100 - 500 Reputation Level)pette.n User rank is Corporal (100 - 500 Reputation Level) 
Time spent in forums: 5 Days 10 h 21 m 2 sec
Reputation Power: 5
all sites' execute permissions are set as "scripts only".

Reply With Quote
  #12  
Old February 5th, 2006, 02:18 PM
Steph3n Steph3n is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Feb 2006
Posts: 22 Steph3n User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 2 h 39 m 28 sec
Reputation Power: 0
Something else you can do is monitor if he has any hidden process using Process Explorer from Sysinternals.

www.sysinternals.com

There are a number of other good tools here including handle, and TCPView. Handle will allow you to find process bound to certian DLLs, and TCPView can help you ID some of the incoming/outgoing traffic patterns that they may be using. But, these are low level tools, they just show you things, what you learn from using them is valueable, but they do NOT give you any idea about what a process does, that is up for you to decide. windows has many built in processes, and you don't want to kill one of them accidentally.

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationIIS > Attacking server


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump