Go Back   Wireless and Wifi Forums > News > Newsgroups > comp.security.misc
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 02-05-2008, 01:53 PM
joseph.rosario@gmail.com
Guest
 
Posts: n/a
Default server is being hacked

every month I am finding either one or two services that are hack
services. I delete the files and clean the service in the registry
then between 1 and 3 months a new hack is on my server. I have
symantec 10.2 and symantec for exchange and a barracuda on the outside
of my network. Can any one help to find the root of this issue. I use
the normal tools like rootkit revealer and aports for scanning my
ports but still they get in. I check my server a few times a day and
usually I catch it within a day but that might be to late. My updates
and patches are up to date. I am running SBS 2003 sp2 and exchange
2003 sp1.

Thank You

Reply With Quote
  #2 (permalink)  
Old 02-05-2008, 02:23 PM
Sebastian G.
Guest
 
Posts: n/a
Default Re: server is being hacked

joseph.rosario@gmail.com wrote:

> every month I am finding either one or two services that are hack
> services. I delete the files and clean the service in the registry
> then between 1 and 3 months a new hack is on my server. I have
> symantec 10.2 and symantec for exchange and a barracuda on the outside
> of my network. Can any one help to find the root of this issue. I use
> the normal tools like rootkit revealer and aports for scanning my
> ports but still they get in. I check my server a few times a day and
> usually I catch it within a day but that might be to late. My updates
> and patches are up to date. I am running SBS 2003 sp2 and exchange
> 2003 sp1.



Ok, and where's the question? Or the problem? Or the news? Sinceyou don't do
anything serious to recover from the compromise, such a sequence of events
is reasonably expected.

Reply With Quote
  #3 (permalink)  
Old 02-05-2008, 02:41 PM
Todd H.
Guest
 
Posts: n/a
Default Re: server is being hacked

"joseph.rosario@gmail.com" <joseph.rosario@gmail.com> writes:

> every month I am finding either one or two services that are hack
> services. I delete the files and clean the service in the registry
> then between 1 and 3 months a new hack is on my server. I have
> symantec 10.2 and symantec for exchange and a barracuda on the outside
> of my network. Can any one help to find the root of this issue. I use
> the normal tools like rootkit revealer and aports for scanning my
> ports but still they get in. I check my server a few times a day and
> usually I catch it within a day but that might be to late. My updates
> and patches are up to date. I am running SBS 2003 sp2 and exchange
> 2003 sp1.



Hi Joseph,

Sorry to hear of your struggles. You need to follow the standard
procedure for recovering from a malware infection:
o remove teh box from the network
o pull data off to another advice and/or image the drive
(including slack space) for later reference or a forensic
analysis
o repartition, reformat and reinstall the OS from original
media

If you want a root cause (or as close to a root cause as you'll get,
depending on the attacker's skill), engage a security firm to do
forensic analysis of the box. This is also sold as "incident
response" service. It's not cheap.

Trying to patch/remove things flagged by a commercial product is like
trying to use a bandaid to cure skin cancer, I'm afraid. You have no
way of knowing you got everything.

Best Regards,
--
Todd H.
http://www.toddh.net/

Reply With Quote
  #4 (permalink)  
Old 02-06-2008, 05:15 AM
Cameron Horton
Guest
 
Posts: n/a
Default Re: server is being hacked

On Tue, 05 Feb 2008 16:23:18 +0100, Sebastian G. wrote:

> joseph.rosario@gmail.com wrote:
>
>> every month I am finding either one or two services that are hack
>> services. I delete the files and clean the service in the registry
>> then between 1 and 3 months a new hack is on my server. I have
>> symantec 10.2 and symantec for exchange and a barracuda on the outside
>> of my network. Can any one help to find the root of this issue. I use
>> the normal tools like rootkit revealer and aports for scanning my
>> ports but still they get in. I check my server a few times a day and
>> usually I catch it within a day but that might be to late. My updates
>> and patches are up to date. I am running SBS 2003 sp2 and exchange
>> 2003 sp1.

>
> Ok, and where's the question? Or the problem? Or the news? Sinceyou don't do
> anything serious to recover from the compromise, such a sequence of events
> is reasonably expected.


Good post.

Are you through fucking your Mother, I'm next!

Reply With Quote
Sponsored Links
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Doctor Who's security & encryption FAQ v21.4 newsmanis@yahoo.com.au alt.computer.security 0 10-10-2007 09:34 PM
Changing from peer-to-peer to server based environment JRC alt.internet.wireless 1 11-08-2006 05:40 PM
[SSL-Talk List FAQ] Secure Sockets Layer Discussion List FAQ v1.1.1 Shannon Appel comp.security.misc 0 10-19-2005 04:37 AM
[SSL-Talk List FAQ] Secure Sockets Layer Discussion List FAQ v1.1.1 Shannon Appel comp.security.misc 0 08-30-2005 04:26 AM
[SSL-Talk List FAQ] Secure Sockets Layer Discussion List FAQ v1.1.1 Shannon Appel comp.security.misc 0 07-31-2005 04:25 AM


All times are GMT. The time now is 01:52 AM.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45