Microsoft IIS
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
 
 
User Name:
Password:
Remember me
Go Back   ASP Free ForumsSystem AdministrationMicrosoft IIS

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread ASP Free Forums Sponsor:
  #1  
Old February 24th, 2005, 01:29 AM
kakarottt kakarottt is offline
Contributing User
ASP Free Newbie (0 - 499 posts)
 
Join Date: Nov 2004
Posts: 63 kakarottt User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 5 h 6 m 9 sec
Reputation Power: 4
Help! Hacked!

my IIS 5.1 webserver was hacked by some turkish guy named ozan... he was nice enough not to wipe out my default file, but he was able to leave this html file on my server. HOW did he do this, the only port open on my router is port 80.....

i would like to know HOW he did this, and what i can do to prevent it, or prevent any further instances..

thanks.

Im not the hacker type, i find more joy in being constructive than destructive.

Reply With Quote
  #2  
Old February 24th, 2005, 03:12 AM
A2k's Avatar
A2k A2k is offline
Contributing User
ASP Free Newbie (0 - 499 posts)
 
Join Date: Dec 2004
Posts: 166 A2k User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 18 h 44 m 10 sec
Reputation Power: 4
I would consider auditing your IIS_USR account priviledges, and downloading the latest Security patches from Microsoft.

Reply With Quote
  #3  
Old February 24th, 2005, 10:21 AM
banker's Avatar
banker banker is offline
Charging Rhino Wizard
ASP Free Regular (2000 - 2499 posts)
 
Join Date: Dec 2004
Location: 127.0.0.1
Posts: 2,053 banker User rank is Sergeant Major (2000 - 5000 Reputation Level)banker User rank is Sergeant Major (2000 - 5000 Reputation Level)banker User rank is Sergeant Major (2000 - 5000 Reputation Level)banker User rank is Sergeant Major (2000 - 5000 Reputation Level)banker User rank is Sergeant Major (2000 - 5000 Reputation Level)banker User rank is Sergeant Major (2000 - 5000 Reputation Level) 
Time spent in forums: 5 Days 23 h 28 m 28 sec
Reputation Power: 36
The company I work for uses a software package called WebAgain. This program constantly monitors your website for changes (comparing it to the archive copy that you set up) and if it senses a change, it immediately overwrites the change with what is in the archive! This is handy for preventing defacement and hacks. We've never been hacked before, but if we were, it would be immediately fixed!

Reply With Quote
  #4  
Old February 24th, 2005, 10:56 AM
kakarottt kakarottt is offline
Contributing User
ASP Free Newbie (0 - 499 posts)
 
Join Date: Nov 2004
Posts: 63 kakarottt User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 5 h 6 m 9 sec
Reputation Power: 4
Quote:
Originally Posted by A2k
I would consider auditing your IIS_USR account priviledges, and downloading the latest Security patches from Microsoft.


automatic updates are on.. i have norton running 24/7...

do you mean making the site read only?
would that affect my database applications? the databases are held in another directory not in my webserver directory.

Reply With Quote
  #5  
Old February 24th, 2005, 12:22 PM
A2k's Avatar
A2k A2k is offline
Contributing User
ASP Free Newbie (0 - 499 posts)
 
Join Date: Dec 2004
Posts: 166 A2k User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 18 h 44 m 10 sec
Reputation Power: 4
Quote:
Originally Posted by kakarottt
automatic updates are on.. i have norton running 24/7...

do you mean making the site read only?
would that affect my database applications? the databases are held in another directory not in my webserver directory.


the internet guest account need only have read-only access to your wwwroot directory (or equiv). NEVER give write access to the internet guest account. Should you need to allow your users to upload files/access the file system you should provide a way to to this through an appropriate client side interface, or using Windows NT permissions.

You should access your database with a user who has sufficient permissions to do the task that are required, and nothing more. If possible, you should use only stored procedures, because you can manage database permissions better.

If you require any further information, you should refer to your servers'/microsofts' help files, or you can post questions here.

Reply With Quote
  #6  
Old February 25th, 2005, 09:44 PM
freeasphelp's Avatar
freeasphelp freeasphelp is offline
Beyond The Impossible
ASP Free Novice (500 - 999 posts)
 
Join Date: Sep 2003
Location: Shawnee Mission, KS, USA
Posts: 921 freeasphelp User rank is Corporal (100 - 500 Reputation Level)freeasphelp User rank is Corporal (100 - 500 Reputation Level)freeasphelp User rank is Corporal (100 - 500 Reputation Level)freeasphelp User rank is Corporal (100 - 500 Reputation Level) 
Time spent in forums: 4 Days 23 h 25 m 9 sec
Reputation Power: 6
Front Page extentsions are a common way to get defaced. Also if you have dynamic codes, such as ASP or ASP.NET. I disagree with A2k on the whole never give write access to IUSR_MachineName, most hosts give this write, as it is a royal pain to give out this access. My best bet is you got hack through a vuln in Frontpage Extentsions.
__________________
John Shepard
Beyond The Impossible
-----------------------------
Has a post helped you? Please show your apprecitation by clicking the
image in the right upper corner.
Posting code? Put your code between [code] and [/code] tags.
X-Login and X-Send

Reply With Quote
  #7  
Old February 27th, 2005, 08:43 PM
Doug G Doug G is offline
Grumpier Old Moderator
ASP Free God 11th Plane (10000 - 10499 posts)
 
Join Date: Sep 2003
Posts: 10,143 Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level) 
Time spent in forums: 3 Weeks 4 Days 21 h 32 m 23 sec
Reputation Power: 180
Make sure you keep your Windows updates current. I didn't once on a box I forgot was running IIS, and got nimda'd
__________________
======
Doug G
======
I didn't attend the funeral, but I sent a nice letter saying I approved of it. --Mark Twain

Reply With Quote
  #8  
Old February 28th, 2005, 11:13 PM
kakarottt kakarottt is offline
Contributing User
ASP Free Newbie (0 - 499 posts)
 
Join Date: Nov 2004
Posts: 63 kakarottt User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 5 h 6 m 9 sec
Reputation Power: 4
yeah, i got nimda the first time arround..
but apparently someone is trying to hack me again..

they have 27 sessions open..

http://port80.cjb.net/default/?cat=getstats

i recently upgraded to sp2
how can i disable frontpage extentions?

Reply With Quote
  #9  
Old March 2nd, 2005, 11:35 AM
Doug G Doug G is offline
Grumpier Old Moderator
ASP Free God 11th Plane (10000 - 10499 posts)
 
Join Date: Sep 2003
Posts: 10,143 Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level) 
Time spent in forums: 3 Weeks 4 Days 21 h 32 m 23 sec
Reputation Power: 180
You can remove the fp extensions from a website using the IIS management console.

Reply With Quote
Reply

Viewing: ASP Free ForumsSystem AdministrationMicrosoft IIS > Help! Hacked!


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 3 hosted by Hostway