1 day up and my Win2k server was hacked..

Sharky Forums


Results 1 to 10 of 10

Thread: 1 day up and my Win2k server was hacked..

  1. #1
    Hammerhead Shark
    Join Date
    Sep 2000
    Posts
    1,549

    1 day up and my Win2k server was hacked..

    Gotta love the internet. I started up my FTP server for a friend and I get home 4 hours later and my pc has been hacked. There are wonderful directory structures now in the inetpub directory. Gotta love IIS!

    SO, how do I remove the directories that were created? I can't see them from the cmd prompt, but win explorer won't let me delete them. I get a "can't read from source" error.
    Last edited by Tripitz; 07-08-2003 at 01:20 PM.

  2. #2
    Great White Shark
    Join Date
    Nov 2000
    Posts
    21,595
    Have you tried using dir /x to display short names (8.3 format)?

    IIS, exspecilly version 6, can be bullet proof, but you've got to set it up that way. I've never had a successful crack of my IIS server. Many have tried as I get very large error logs each day.

  3. #3
    gran tiburón blanco ewitte's Avatar
    Join Date
    Jul 2002
    Location
    Houston, TX mostly. Lima, Peru partiallly.
    Posts
    7,394
    Originally posted by ua549
    Have you tried using dir /x to display short names (8.3 format)?

    IIS, exspecilly version 6, can be bullet proof, but you've got to set it up that way. I've never had a successful crack of my IIS server. Many have tried as I get very large error logs each day.
    Sometimes they create directories with special characteristics and the system will not let you remove them. Usually PRN, LPT1 and my favorite the directory without ANY NTFS permissions... not even the administrator can do anything with it. Out of the 2 times I saw this once I was able to remove everything. The second time I had to move the real data off, format and move it back on. Apparantly there is some utility based off of Unix that fixes them but I've never used it. I touch a good 3-4 sites a day so statistically IIS configured correctly holds up since I've only seen it twice in 2 years.

    Eric
    Last edited by ewitte; 07-08-2003 at 03:53 PM.

  4. #4
    Hammerhead Shark
    Join Date
    Sep 2000
    Posts
    1,549
    Originally posted by ewitte


    Sometimes they create directories with special characteristics and the system will not let you remove them. Usually PRN, LPT1 and my favorite the directory without ANY NTFS permissions... not even the administrator can do anything with it. Out of the 2 times I saw this once I was able to remove everything. The second time I had to move the real data off, format and move it back on. Apparantly there is some utility based off of Unix that fixes them but I've never used it. I touch a good 3-4 sites a day so statistically IIS configured correctly holds up since I've only seen it twice in 2 years.

    Eric
    You're right... Unfortunately, I forced admin full rights on everything and still no go. What really scares me is that now the files are GONE. I still cannot delete them. I blocked port 21 access at my firewall and obviously shutdown the IIS and FTP service. I think this will require a format which is very annoying. I don't have enough space elsewhere to put some of the data that I have. (its a large drive)

    C:\Inetpub\ftproot\ \ \ \com4\F@#KOFF \con\ScanneD \com7\by \com1\Sh0rZ\com9\TaGGeD \lpt1\by \lpt1\Sh0rZ\con\ \with Neo1907´s PuB-tAgGeR \lpt3\uPPed \com3\BY \aux\Sh0rZ\com3

    Like I said, there were more. There was a directory in german indicating that it was "what women want", with 1 .exe file in the directory and what looks to be compressed files. those are now gone without me deleting them.

  5. #5
    gran tiburón blanco ewitte's Avatar
    Join Date
    Jul 2002
    Location
    Houston, TX mostly. Lima, Peru partiallly.
    Posts
    7,394
    Originally posted by Tripitz


    You're right... Unfortunately, I forced admin full rights on everything and still no go. What really scares me is that now the files are GONE. I still cannot delete them. I blocked port 21 access at my firewall and obviously shutdown the IIS and FTP service. I think this will require a format which is very annoying. I don't have enough space elsewhere to put some of the data that I have. (its a large drive)

    C:\Inetpub\ftproot\ \ \ \com4\F@#KOFF \con\ScanneD \com7\by \com1\Sh0rZ\com9\TaGGeD \lpt1\by \lpt1\Sh0rZ\con\ \with Neo1907´s PuB-tAgGeR \lpt3\uPPed \com3\BY \aux\Sh0rZ\com3

    Like I said, there were more. There was a directory in german indicating that it was "what women want", with 1 .exe file in the directory and what looks to be compressed files. those are now gone without me deleting them.
    Read my post in the "Technical support q/a" forum
    Last edited by ewitte; 07-08-2003 at 04:42 PM.

  6. #6
    Great White Shark vertices's Avatar
    Join Date
    Sep 2000
    Location
    Palm Coast, FL
    Posts
    6,001
    Originally posted by Tripitz

    C:\Inetpub\ftproot\ \ \ \com4\F@#KOFF \con\ScanneD \com7\by \com1\Sh0rZ\com9\TaGGeD \lpt1\by \lpt1\Sh0rZ\con\ \with Neo1907´s PuB-tAgGeR \lpt3\uPPed \com3\BY \aux\Sh0rZ\com3
    ROFL!!

    You got scanned and they created a pub on your machine. People do this and FXP files to it and distribute your addy to everyone in the FXP scene and they all DL files from your stuff.

    Heh heh..I use to FTP to addys like that all the time to get "stuff".

    Were you set to allow anonymous connects?
    Last edited by vertices; 07-08-2003 at 10:28 PM.

  7. #7
    Zoom-Zoom! soupnazi's Avatar
    Join Date
    May 2002
    Location
    Vancouver, BC
    Posts
    15,097
    Someone named "Bill Gates" hacked my Winxp pro desktop computer, right when I was downloading Zonealarm. He commented on my nice sportscar wallpaper, then changed to porn wallpaper.
    Spoiler

  8. #8
    By the Power of Greyskull Colossus's Avatar
    Join Date
    Jul 2002
    Location
    Boston, MA
    Posts
    21,140
    You know I never have been hacked on any of my Linux or Windows servers.. Well none that I am aware of

    I feel for you... I have about 8 Linux servers live since 94 and they have NEVER been hacked! I have a massive log file of all the attempts but not a single successes to my knowledge..

    I have had various Windows NT from 3.51, NT 4.0, 2000, 2003 now online that I manage with my consultant firm.. So far no one made it in

    *knocks on wood!!!!*

    Im sorry that it had happened... I know it sucks! But it might be a good idea to reinstall.. Since most hackers would leave backdoors, etc to allow them access later..

    Intel I9 14900K|ASUS - MAXIMUS Z790 HERO|ASUS GTX 1080 Ti|64GB G.Skill|(3) Samsung 990 Pro 4TB NVME |Custom water cooling||Alienware AW3423DW 34" OLED

    288TB Plex server (UNRAID)
    (16) WD Red Pro 20TB

  9. #9
    Not Wurm Isezumi's Avatar
    Join Date
    Dec 2001
    Location
    SAN DIEGO, CA
    Posts
    7,267
    Yet another idea that I wish Microsoft would steal...

    Make Admin like Root in *nix. Absoluete authority, no questions asked.

  10. #10
    Tiger Shark
    Join Date
    Oct 2001
    Location
    Tarakan Island "???"
    Posts
    719
    When they hack, what they really want?
    I know they can do all the things but are they really damaging your PC? (e.g. delete your MP3, documents, etc)

    Or they just play for fun (Get in your PC and put their name in your PC - Wanna be famous).

    Vodude => the fans of 3dfx voodoo
    (not a vodka drinker and not a Vodafone user)
    Dedicated to my V3000 (21/6/99-18/12/02), which I forgot where have I put it.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •