This is a multi-part message in MIME format.

------=_NextPart_000_0043_01C45CFF.AC8AA600
Content-Type: text/plain;
charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

hi
someone was hacked my site
i have 2 servers :
web--> IIS 5 / w2k adv Srv IIS lockdown
sql--> SQL2k / w2k adv Srv

i found the web srv doing "beeps"
soon i found it serves html pages
but don't serves asp with an error like
"Error in the server application"

sql srv lost sa password
and don't recognize the local admin
then i can't access to sql applications

except of that,
servers appears to work normal

the web srv log is saying
that attacked the iwam_
and many "login misses" under DCOMSCM
and then, "login hits"

i go now to restore
my backup and images
but
what can i do to prevent the next attack ?
how can i protect better the site ?

thanks




--=20
atte,
Hern=E1n Castelo
SGA - UTN - FRBA

------=_NextPart_000_0043_01C45CFF.AC8AA600
Content-Type: text/html;
charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META http-equiv=3DContent-Type content=3D"text/html; =
charset=3Diso-8859-1">
<META content=3D"MSHTML 6.00.2800.1400" name=3DGENERATOR>
<STYLE></STYLE>
</HEAD>
<BODY bgColor=3D#ebf3fc>
<DIV>
<DIV><FONT face=3DArial size=3D2>hi</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>someone was hacked my site</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>i have 2 servers :</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>web--&gt; IIS 5 / w2k adv Srv IIS=20
lockdown</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>sql--&gt; SQL2k / w2k adv =
Srv</FONT></DIV>
<DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
<DIV><FONT face=3DArial size=3D2>i found the web srv </FONT><FONT =
face=3DArial=20
size=3D2>doing "beeps"</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>soon i found it serves html =
pages</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>but don't serves asp with an error=20
like</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>"Error in the server =
application"</FONT></DIV>
<DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
<DIV><FONT face=3DArial size=3D2>sql srv lost sa password</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>and don't recognize the local =
admin</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>then i can't access to sql=20
applications</FONT></DIV>
<DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
<DIV><FONT face=3DArial size=3D2>except of that,</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>servers appears to work =
normal</FONT></DIV>
<DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
<DIV><FONT face=3DArial size=3D2>
<DIV><FONT face=3DArial size=3D2>the web srv log is saying</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>that attacked the iwam_</FONT></DIV>
<DIV>and many "login misses" under DCOMSCM</DIV>
<DIV>and then, "login hits"</DIV></FONT></DIV>
<DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
<DIV><FONT face=3DArial size=3D2>i go now to restore</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>my backup and images</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>but</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>what can i do to prevent the next =
attack=20
?</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>how can i protect better the site =
?</FONT></DIV>
<DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
<DIV><FONT face=3DArial size=3D2>thanks</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>&nbsp;</DIV>
<DIV><BR></DIV></FONT></DIV>
<DIV><FONT face=3DArial size=3D2><BR>-- <BR>atte,<BR>Hern=E1n =
Castelo<BR>SGA - UTN -=20
FRBA<BR></FONT></DIV></BODY></HTML>

------=_NextPart_000_0043_01C45CFF.AC8AA600--

Re: help: site hacked by emccarty

emccarty
Mon Jun 28 15:48:15 CDT 2004

1). Stronger Passwords
2). Run All Updates to windows
3). Run all updated to IIS and SQL Server
4). Run Lockdown tool

I dont see enough information in your post to tell you what happened,
check IIS Logs, Check SQL Logs, Check Event Logs, check to see what
netstat says when you run netstat -a.

E.


Hernán Castelo <hcastelo@cedi.frba.utn.edu.ar> wrote in message news:<uob7ghRXEHA.4000@TK2MSFTNGP09.phx.gbl>...
> hi
> someone was hacked my site
> i have 2 servers :
> web--> IIS 5 / w2k adv Srv IIS lockdown
> sql--> SQL2k / w2k adv Srv
>
> i found the web srv doing "beeps"
> soon i found it serves html pages
> but don't serves asp with an error like
> "Error in the server application"
>
> sql srv lost sa password
> and don't recognize the local admin
> then i can't access to sql applications
>
> except of that,
> servers appears to work normal
>
> the web srv log is saying
> that attacked the iwam
> and many "login misses" under DCOMSCM
> and then, "login hits"
>
> i go now to restore
> my backup and images
> but
> what can i do to prevent the next attack ?
> how can i protect better the site ?
>
> thanks

Re: help: site hacked by Hernán

Hernán
Tue Jun 29 14:56:15 CDT 2004

this is a summary of the log files
please tell me if you recognize
some entry

THanks


web/ sec
------------
681 on IWAM
529 on DCOMSCM thru IWAM
612 policy changed
514 on LSAsrv.dkk, kerberos.dll, schannell, msv1_0:NTLM ...
518 on RASSFM

web/ sec
------------
4 IIS stopped
4156 MSDTC info CM "session idle timeout over, tearing down the session"
4156 MSDTC client "session idle timeout over, tearing down the session"
1704 SceCli "policy change applied"
4097 MSDTC started ...

web/ sys
------------
36 w3svc can't load /LM/w3SVC/2/Root
10004 DCOM "overlaped I/O" thru IWAM



sql /sec log:
------------
529, 680 on sql service account
515 on rasman
514 on LSAsrv.dkk, kerberos.dll, schannell, msv1_0:NTLM ...

sql/ sys log:
------------
64 by w32time
7000 - can't start SCM service contol manager
7001 - sql not available - SqlServerAgent

sql/ app log
------------
208 - SqlSrvAg can't do backup
17177 MsSqlSrv not available
4097 MSDTC SVC not available



--
atte,
Hernán Castelo
SGA - UTN - FRBA

"E." <emccarty@gmail.com> escribió en el mensaje
news:425505ef.0406281248.1cf052b1@posting.google.com...
> 1). Stronger Passwords
> 2). Run All Updates to windows
> 3). Run all updated to IIS and SQL Server
> 4). Run Lockdown tool
>
> I dont see enough information in your post to tell you what happened,
> check IIS Logs, Check SQL Logs, Check Event Logs, check to see what
> netstat says when you run netstat -a.
>
> E.
>
>
> Hernán Castelo <hcastelo@cedi.frba.utn.edu.ar> wrote in message
news:<uob7ghRXEHA.4000@TK2MSFTNGP09.phx.gbl>...
> > hi
> > someone was hacked my site
> > i have 2 servers :
> > web--> IIS 5 / w2k adv Srv IIS lockdown
> > sql--> SQL2k / w2k adv Srv
> >
> > i found the web srv doing "beeps"
> > soon i found it serves html pages
> > but don't serves asp with an error like
> > "Error in the server application"
> >
> > sql srv lost sa password
> > and don't recognize the local admin
> > then i can't access to sql applications
> >
> > except of that,
> > servers appears to work normal
> >
> > the web srv log is saying
> > that attacked the iwam
> > and many "login misses" under DCOMSCM
> > and then, "login hits"
> >
> > i go now to restore
> > my backup and images
> > but
> > what can i do to prevent the next attack ?
> > how can i protect better the site ?
> >
> > thanks



Re: site hacked by hcastelo

hcastelo
Tue Jun 29 14:57:56 CDT 2004

This is a multi-part message in MIME format.

------=_NextPart_000_0035_01C45DFA.39798950
Content-Type: text/plain;
charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

this is a summary of the log files
please tell me if you recognize
some entry

THanks


web/ sec
------------
681 on IWAM
529 on DCOMSCM thru IWAM
612 policy changed=20
514 on LSAsrv.dkk, kerberos.dll, schannell, msv1_0:NTLM ...
518 on RASSFM

web/ sec
------------
4 IIS stopped
4156 MSDTC info CM "session idle timeout over, tearing down the session"
4156 MSDTC client "session idle timeout over, tearing down the session"
1704 SceCli "policy change applied"
4097 MSDTC started ...

web/ sys
------------
36 w3svc can't load /LM/w3SVC/2/Root
10004 DCOM "overlaped I/O" thru IWAM



sql /sec log:
------------
529, 680 on sql service account
515 on rasman
514 on LSAsrv.dkk, kerberos.dll, schannell, msv1_0:NTLM ...

sql/ sys log:
------------
64 by w32time
7000 - can't start SCM service contol manager
7001 - sql not available - SqlServerAgent

sql/ app log
------------
208 - SqlSrvAg can't do backup
17177 MsSqlSrv not available
4097 MSDTC SVC not available

------=_NextPart_000_0035_01C45DFA.39798950
Content-Type: text/html;
charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META http-equiv=3DContent-Type content=3D"text/html; =
charset=3Diso-8859-1">
<META content=3D"MSHTML 6.00.2800.1400" name=3DGENERATOR>
<STYLE></STYLE>
</HEAD>
<BODY bgColor=3D#ebf3fc>
<DIV>
<DIV>this is a summary of the log files</DIV>
<DIV>please tell me if you recognize<BR>some entry</DIV>
<DIV>&nbsp;</DIV>
<DIV>THanks</DIV>
<DIV>&nbsp;</DIV>
<DIV>&nbsp;</DIV>
<DIV>web/ sec</DIV>
<DIV>------------</DIV>
<DIV>681 on IWAM</DIV>
<DIV>529 on DCOMSCM thru IWAM</DIV>
<DIV>612 policy changed </DIV>
<DIV>
<DIV>514 on LSAsrv.dkk, kerberos.dll, schannell, msv1_0:NTLM ...</DIV>
<DIV>518 on RASSFM</DIV>
<DIV>&nbsp;</DIV></DIV>
<DIV>
<DIV>web/ sec</DIV>
<DIV>------------</DIV>
<DIV>4 IIS stopped</DIV>
<DIV>4156 MSDTC info CM "session idle timeout over, tearing down the=20
session"</DIV>
<DIV>
<DIV>4156 MSDTC client "session idle timeout over, tearing down the=20
session"</DIV></DIV>
<DIV>1704 SceCli "policy change applied"</DIV>
<DIV>4097 MSDTC started ...</DIV>
<DIV>&nbsp;</DIV>
<DIV>
<DIV>
<DIV>web/ sys</DIV>
<DIV>------------</DIV>
<DIV>36 w3svc can't load &nbsp;/LM/w3SVC/2/Root</DIV>
<DIV>10004&nbsp;DCOM&nbsp;"overlaped I/O" thru IWAM</DIV>
<DIV>&nbsp;</DIV></DIV></DIV></DIV>
<DIV>&nbsp;</DIV>
<DIV>&nbsp;</DIV>
<DIV>sql /sec log:</DIV>
<DIV>------------</DIV>
<DIV>529, 680 on sql service account</DIV>
<DIV>515 on rasman</DIV>
<DIV>514 on LSAsrv.dkk, kerberos.dll, schannell, msv1_0:NTLM ...</DIV>
<DIV>&nbsp;</DIV>
<DIV>sql/ sys log:</DIV>
<DIV>
<DIV>------------</DIV></DIV>
<DIV>64 by w32time</DIV>
<DIV>7000 -&nbsp;can't start SCM service contol manager</DIV>
<DIV>7001 - sql not available - SqlServerAgent</DIV>
<DIV>&nbsp;</DIV>
<DIV>sql/ app log</DIV>
<DIV>
<DIV>------------</DIV>
<DIV>208 - SqlSrvAg can't do backup</DIV>
<DIV>17177 MsSqlSrv not available</DIV>
<DIV>4097 MSDTC SVC not available</DIV></DIV>
<DIV>&nbsp;</DIV></DIV></BODY></HTML>

------=_NextPart_000_0035_01C45DFA.39798950--