|
|||||||||||
|
RE: First time security issue.
From: Bojan Zdrnja <Bojan.Zdrnja(at)LSS.hr>
Date: Tue Jul 22 2003 - 22:58:11 EDT I'd agree with Harlan here. However, the process itself depends upon the business needs in front of the OP. In any case, my suggestion would be to reinstall the system and apply all patches on it. Also, before this, OP should make a HDD image copy so he can do forensics on it and eventually find out what happened with it. According to what the OP wrote, and as Harlan said as well, I doubt this is related to any Windows NT rootkit. Most of the cases I had experience with, and which had ServU/IRC-bot being setup, are related to script kiddies which just want to collect more machines and use public well-known exploits (or weak passwords etc.). Best regards, Bojan Zdrnja Received on Wed Jul 23 13:13:11 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:02:12 EDT |
||||||||||
|
|||||||||||