hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : Hosting Security and Technology : My server has been hacked, desperately need help
Reply

Hosting Security and Technology Configuring and optimizing web hosting servers and operating systems, developing administration scripts, building servers, protecting against hackers, and general security (SSL certificates, etc.)
Forum Jump

My server has been hacked, desperately need help

Reply Post New Thread In Hosting Security and Technology Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 09-01-2007, 02:11 AM
jerry2 jerry2 is offline
Newbie
 
Join Date: Mar 2006
Posts: 20

My server has been hacked, desperately need help


Hi there all...

I don't think I am a web administrator professional, but I do have a dedicated server with web site for a year. Until the attacker got in... Let me explain.

I have Windows 2003, all security patches, I run Plesk 8.2 and nothing much else. I use MySQL as a database with port 3306 open so I can connect from the outside (password protected also). I do use strong passwords on my Plesk, administrator etc. I use standard microsoft FTP, Windows 2003 Firewall and connect through Plesk or remote connection.

Somebody has been able to penetrate to my Admin remote desktop :-( I found strange windows open when I connected and in the log there was an indication of the printer driver load. The printer name was one I don't have and my Remote connection has Printers off. The attacker although smart did connect with his printer and that was visable in log. When he terminated the session I found his IP.

I have since changed my administrator password but it doesn't help, he was in again today. He didn't do any harm up to now I think, I checked for viruses and Spyware.

I don't know what to do any more. He can do whatever he wants and if I don't know how he is getting access to my admin account I can not stop him. I blocked today with IPSec the whole IP range of his provider, but as he is smart he can hack another computer and connect to me from him (maybe he has already done that and the IP was from a hacked server). This is no solution. I need to patch the hole.

I use ASP scripts but I don't think one can gain access to the whole admin by them, maybe only get access to my database (if I would make a mistake and wouldn't protect for the injections or some other things).

I am desperate. Plese, if anybody has some ideas what can I do, how do I "catch" him, I mean patch the hole, please let me know.

Thank you

Jerry

PS - I had an idea to block all IP's to port 3389 (Remote desktop) except my IP. But I am a little scared to do that not to lock myself out. And even in that case, if he knows admin password he can get in some other way than using remote desktop, can't he?

Reply With Quote


Sponsored Links
  #2  
Old 09-01-2007, 09:13 AM
jerry2 jerry2 is offline
Newbie
 
Join Date: Mar 2006
Posts: 20
Ok, I found out hacker planted a NetMonInstaller service and WinPcap. Can anybody tell me what info can he get with this sniffer?

But how did he get in in the first place?

Jerry

Reply With Quote
  #3  
Old 09-01-2007, 11:23 AM
ximi ximi is offline
WHT Addict
 
Join Date: Aug 2007
Location: Minneapolis
Posts: 109
With the sniffer, he can log all of your traffic, so he has access to quite a lot with it.

Make an image of the OS and analyze it later. Do a full reinstall now.

Reply With Quote
Sponsored Links
  #4  
Old 09-01-2007, 11:38 AM
jerry2 jerry2 is offline
Newbie
 
Join Date: Mar 2006
Posts: 20
It won't help as I don't know how he got in the first place. He used Abel & Cain.

Reply With Quote
  #5  
Old 09-01-2007, 12:00 PM
Tom P Tom P is offline
Web Hosting Guru
 
Join Date: Dec 2004
Location: United Kingdom
Posts: 301
Your best option, as what ximi said to do.

Create a backup of everything and then get the datacenter to format and reinstall (or do it over KVM if the DC has it). When its re-installed I would then consider paying a company to secure down the system for you, if this is for business use then I would definately recommened getting a consultant to run things by (such as leaving MySQL open, although needed you need to lock it down).

Consider getting them to install an intrusion detection system and monitor failed logins on everything, it could have been that he is brute forcing (you've said you have strong passwords, but you never know).

Also ensure that there is nothing on the PC you are connecting from, as if you have a keylogger on your system then you are always going to have the same problem

> Backup
> Format
> Consult

Good luck!

Reply With Quote
  #6  
Old 09-01-2007, 12:13 PM
jerry2 jerry2 is offline
Newbie
 
Join Date: Mar 2006
Posts: 20
Thanx for the tips. I do have some knowledges of how things work but I guess something was still open.

Reply With Quote
  #7  
Old 09-02-2007, 12:56 AM
Fernis Fernis is offline
Junior Guru Wannabe
 
Join Date: Dec 2005
Location: Houma, LA
Posts: 66
You might want to consider scanning your system for rootkits using Rootkit Revealer.

Here is a link to download a copy of the utility.

http://filehippo.com/download_rootkit_revealer/

__________________
Owner/President
Booyah! Web Hosting, L.L.C.
Great Personal Service
Experience the Booyah! Difference

Reply With Quote
  #8  
Old 09-02-2007, 01:23 AM
oneavenue oneavenue is offline
WHT Addict
 
Join Date: Feb 2002
Location: Tampa, Florida
Posts: 153
1. Backup all your files
2. Format the server drive(s)
3. Re-install Windows server
4. Install Anti-Virus
5. Secure the server ( Hire a specialist if you have to )
6. Patch/Update the Server
7. Scan your backup files carefully
8. Restore your files to new server install
9. Be very careful of what FREE scripts you install on your server ( FREE scripts can cost allot of money sometimes! )
10. Ask yur provider if they provided Managed firewall service or get a hardware firewall.

Good luck

__________________
|| One Avenue Networks ||
cPanel & Parallels Pro Reseller Hosting | Dedicated Hosting | Server Colocation
Non-Oversubscribed Bandwidth | Non-Oversubscribed Servers | 99.9% Network Uptime

Reply With Quote
Reply

Related posts from TheWhir.com
Title Type Date Posted
SwaggSec Hackers Release 900 Admin Credentials from China Telecom Attack Web Hosting News 2012-06-04 15:24:03
Whistleblower Site Cryptome Hacked, Infects PCs with Drive-By Exploits Web Hosting News 2012-02-14 14:48:24
Security Firm ArtSec Launches Website and Server Migration Service Web Hosting News 2011-12-09 18:43:03
Bangladeshi Hacker TiGER-M@TE Targets InMotion Hosting Web Hosting News 2011-09-26 15:24:05
Toshiba Server Breach Compromises Email Information of 681 Customers Web Hosting News 2011-07-18 17:29:46


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?