Hackers struck a newsgroup server I came in contact with last night. They
sent out bogus emails to people on the recipient list and sat back and
watched the finger-pointing fun.
-----Original Message-----
From: Dunn, Nancy [mailto:ndunn@...]
Sent: Thursday, May 17, 2001 2:27 PM
To: 'vantage@yahoogroups.com'
Subject: RE: [Vantage] HELP !!! Server security
Dan,
With a dialup I won't think you were to vulnerable, or someone would go to
much trouble to get to your server.
I'm not sure about SBS, but here is some information I found helpful.
I check logfiles for W2K at:
\winnt\system32\logfiles\I have 2 log folder here. (looks like you are
looking in the right place).
If you have IIS there have been some critical patches out this month. My
server is being tested by hackers way to much lately, other people in my
Exchange group are having the same problem.
Here are a couple sites I found helpful.
www.microsoft.com\technet\security/iischk.asp
http://grc.com/pw/patchwork.htm
www.cert.org/tech_tips/root_compromise.html
Hope this helps a little bit, and I don't sound as dumb as I feel about this
subject.
Nancy Dunn
Winco Industries Inc.
-----Original Message-----
From: Dan Shallbetter [mailto:dans@...]
Sent: Thursday, May 17, 2001 11:29 AM
To: vantage@yahoogroups.com
Subject: [Vantage] HELP !!! Server security
We are running SBS 4.5 using a 56k dial connection. I had a warning in my
event viewer that the server was unable to logon NT account
'anonymous@...' due to bad user name or logon. The time was
3:13 AM there would normally be no system activity then. Is it possible that
someone has hacked in to my server and is trying to get back out on? I have
looked at my log files in WINNT\system32\msplogs but did not see any
corresponding activity for the time frame. Is there somewhere else I should
look?
Thanks
Dan Shallbetter
States Electric Mfg.
P.S we got the President here in Mpls. today looking at how us Swedes build
power plants trying to bail CA. out of it's mess :-))
To access the Files Section of our Yahoo!Group for Report Builder and
Crystal Reports and other 'goodies', please go to:
http://groups.yahoo.com/group/vantage/files/. Note: You must have already
linked your email address to a yahoo id to enable access.
Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/
To access the Files Section of our Yahoo!Group for Report Builder and
Crystal Reports and other 'goodies', please go to:
http://groups.yahoo.com/group/vantage/files/. Note: You must have already
linked your email address to a yahoo id to enable access.
Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/
sent out bogus emails to people on the recipient list and sat back and
watched the finger-pointing fun.
-----Original Message-----
From: Dunn, Nancy [mailto:ndunn@...]
Sent: Thursday, May 17, 2001 2:27 PM
To: 'vantage@yahoogroups.com'
Subject: RE: [Vantage] HELP !!! Server security
Dan,
With a dialup I won't think you were to vulnerable, or someone would go to
much trouble to get to your server.
I'm not sure about SBS, but here is some information I found helpful.
I check logfiles for W2K at:
\winnt\system32\logfiles\I have 2 log folder here. (looks like you are
looking in the right place).
If you have IIS there have been some critical patches out this month. My
server is being tested by hackers way to much lately, other people in my
Exchange group are having the same problem.
Here are a couple sites I found helpful.
www.microsoft.com\technet\security/iischk.asp
http://grc.com/pw/patchwork.htm
www.cert.org/tech_tips/root_compromise.html
Hope this helps a little bit, and I don't sound as dumb as I feel about this
subject.
Nancy Dunn
Winco Industries Inc.
-----Original Message-----
From: Dan Shallbetter [mailto:dans@...]
Sent: Thursday, May 17, 2001 11:29 AM
To: vantage@yahoogroups.com
Subject: [Vantage] HELP !!! Server security
We are running SBS 4.5 using a 56k dial connection. I had a warning in my
event viewer that the server was unable to logon NT account
'anonymous@...' due to bad user name or logon. The time was
3:13 AM there would normally be no system activity then. Is it possible that
someone has hacked in to my server and is trying to get back out on? I have
looked at my log files in WINNT\system32\msplogs but did not see any
corresponding activity for the time frame. Is there somewhere else I should
look?
Thanks
Dan Shallbetter
States Electric Mfg.
P.S we got the President here in Mpls. today looking at how us Swedes build
power plants trying to bail CA. out of it's mess :-))
To access the Files Section of our Yahoo!Group for Report Builder and
Crystal Reports and other 'goodies', please go to:
http://groups.yahoo.com/group/vantage/files/. Note: You must have already
linked your email address to a yahoo id to enable access.
Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/
To access the Files Section of our Yahoo!Group for Report Builder and
Crystal Reports and other 'goodies', please go to:
http://groups.yahoo.com/group/vantage/files/. Note: You must have already
linked your email address to a yahoo id to enable access.
Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/