If you restrict access (with a firewall) to Terminal Services, you won't really need to log the IP anymore, as they won't be able to get to the server anymore.
However, if you really want to know the IP address of the attacker, use the logging function of the firewall to log the IP address of anyone trying to access the TS ports. First, restrict access to the TS ports to whatever IP you will be coming from. Second, set the firewall to log all attempts to access the TS ports from all other IP addresses.
Since you used the term "dedicated Win2K webserver" I assume this must be a remote server, and you can't install a hardware firewall - at least not without additional monthly fees. Here are some software firewalls that I've seen mentioned many times:
http://www.zonealarm.com
http://blackice.iss.net/
http://www.famhost.com/sup
If you can use a hardware firewall, definitely do so. However, if it's not possible, one of these should do the trick.
Good luck,
Jeff
Main Topics
Browse All Topics





by: fz2hqsPosted on 2004-02-23 at 01:38:59ID: 10430668
The simple answer here would be to get a firewall. The firewall would either deny or silently drop requests from the "hacker" and you can log those, simalarly you can define certain ACL's to allow you in