Dont have a firewall installed. Please suggest a good and cheap one if possible.
Main Topics
Browse All TopicsHi
We have a dedicated server 2003 OS. Recently we found that there were tons of new folders which contained some hacked stuff. I dont know how they got to the folders in the first place. There are folders in the inetpub folders and outside it as well.
If we are a self managed server... do we need to do some settings to prevent such access to the hard disk over the net ?
KC
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Yes, sorry, should have realised it was IIS 6,
I prefer to use Sygate
http://www.sygate.com/
however most people would probably tell you to use Zone Alarm
http://www.zonelabs.com/st
Both are free for home use and and relativly cheap to buy for an organisation.
Chops123, =)
I disagree with going with a software firewall only. I would suggest using a linksys hardware firewall or Dlink. This will help protect your network a lot better than a software firewall, cost you about 70 bucks. If you decided you really want a software firewall or just don't have the 70 bucks check out this free version of Sygate Personal, http://smb.sygate.com/prod
Lets move on to see what damage has been done, so we can begin to patch and repair,
Detection / Prevention:
First, run a virus scan @ http://housecall.trendmicr
- Even if you already have virus protection. This will help identify any backdoors that might be in use to easily access your system. Most lilky they're just accessing through a specigic port via FTP, telnet and using your system to store illegal software.
Now, we want to see what ports you have open. So lets run some online port scans:
Sygate online port scan(s): http://scan.sygate.com I'd run the Quick Scan, Trojan Scan, TCP Scan(depending on results).
Now, I would go into IIS snapin and check the footer. See if anything there has been modified. There's a virus from a few months ago that took advantage of this to spread, as well as a new one released last week.
Please advise results of scan(s) & test(s) and advise for further instructions/suggestions.
Good Luck,
Jorden
ok sounds like your server is pretty open and you need to re-evaluate your security. here is the basic guide from microsoft on what you can do. start off with the basics before you start to build an elaborate strategy. microsoft has a security baseline scanner that you can run on the machine to give you an idea of potential flaws. its not the greatest tool but its a start. iis 6 that comes with windows 2003 comes in a locked down state to iis lockdown and urlscan are not needed. some but some people still install urlscan as a way to prevent unauthorized url commands. i agree with others that a firewall is a must. you can use the windows firewall if you are strapped for cash but i would even just shell out for a simple linksys firewall you can configure to block all ports except 80/443. this will eliminate the potential avenues of hacking.
microsoft iss info:
http://www.microsoft.com/s
Chops123,
I would recommend setting up a firewall with an old beater PC (an old pentium would do nicely), and IPCop. www.ipcop.org
You can use it along with 2 nics to set up a firewall with proven, stable linux based utilities. Once you have it set up, anything that you need to configure can be done through IPCops web interface.
IPCop makes it pretty painless if you read the docs first. If you have an old PC, this is the way to go (aka free)! IPCop is free.
Jared
I would put a hardware firewall in place on the networks perimeter, and I would recommend a good one like a PIX. If you only have a DSL connection or cable connection a Cisco 831 router with IOS Firewall woudl also work. Whatever you choose take the time to set it up correctly and log its activities. It is more than worth your time and money to do it the right way. Also secure the server, if you don't need IIS don't install it. Do your research and only run the services that you need. Keep the server updated and keep an eye on the logs.
Chops, =)
Do you have an Ipod? If not, the port 6969 is definitly a trojan/backdoor.
Port 6969
Netwin DSMTP v2.7q remote-root exploit by noir will leave a root shell at this port.
or could be:
http://www.sarc.com/avcent
I recommend running the trendmicro virus scan, also installing sygate atleast until you can buy a hardware firewall.
let me know details, I'll give more recommendations when I get off work.
good luck,
Jorden
Also, found this at eeye.com:
http://seclists.org/lists/
Try to telnet to your webserves IP + port 6969 ex. telnet 64.121.121.55 6969 , this is good to see what that port is being used for, sometimes your see a hackers welcome screen or tag, which can help identify the exact exploit/backdoor in use.
IIS 6 is a lot more secure than IIS 5 and earlier versions. However, there are cross-site scripting exploits even for IIS6.
Regardless of how, your server is or was compromised and you havea vulnerable port open.
Please advise,
Jorden
Business Accounts
Answer for Membership
by: anil_uPosted on 2004-11-29 at 02:56:48ID: 12694798
inetpub folder would suggest IIS is being used. The first thing to do is use the IIS Lockdown tool to stop everything you dont need in IIS. ownloads/d etails.asp x? FamilyID =dde9efc0- bb30-47eb- 9a61-fd755 d23cdec&di splaylang= en
http://www.microsoft.com/d
The next would be to make sure that the server 03 has been patched with the latest updates available from www.microsoft.com
Do you have a firewall, make sure that all unessecary ports a blocked.