How is this occuring??

S

Steve Grosz

I am checking on this more and more, but lately I have been having users
appear on my system with accounts with usernames such as bob1$.

I know I'm not adding these users (who are also in the Administrators
group).

I've recently applied SP2 for Win2003. I leave FTP up and running as little
as possiblen and only have DNS and IIS running with a software firewall in
place.

Am I missing something??
 
R

Roger Abell [MVP]

Your machine is likely no longer your own kingdom.
If you are seeing accounts show up in your admin group, that is
definitely a sign you have been had.

Roger
 
S

Steve Grosz

So what can be done to correct it??

Roger Abell said:
Your machine is likely no longer your own kingdom.
If you are seeing accounts show up in your admin group, that is
definitely a sign you have been had.

Roger
 
R

Roger Abell [MVP]

Steve Grosz said:
So what can be done to correct it??

The first thing is to try to minimize the damages, such as preventing
anything further from happening. Note however that, if assessment
of your box being owned is correct, this first thing is only for the
sake of buying some time in which one a) plans for some sort of
continuity of operations during the rebuild, and, b) trys to find out
what one did / did-not do wrong / right so that the new rebuilt
system does not go down the same road.

If you have been had, there is little you can do except for start
over. You can attempt to "clean up", but you can never really
gain 100% certainty that you are done.

From what you stated, I will not use the FTP that comes with
Windows for non-anonymous access at all (not that it is badly
implemented, but because it implies sending credentials over
the wire in the clear), you had a firewall out front (but how was
it configured?), you had IIS running (ditto - how was it configured),
etc.. For an average persons trying to run W2k3, a great place to
start is by turing on the Windows firewall and then connecting the
network wire; and of course, using the Security Configuration
Wizard and keeping up-to-date on patches.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top