Solved

Server 2000 Security question

Posted on 2007-03-21
2
215 Views
Last Modified: 2013-12-04
I manage a windows 2000 server and ive got a watchguard III 700 firewall. Ive noticed in the firebox system manager on the traffic monitor tab, it looks like someone is accessing our system when they should not be. The monitor says it allowed traffic from ip address 125.110.131.76 to different external addresses on my network. They are using port 5900 which i opened to enable remote access for VNC for certain users. There is also many denied attempts to get through the firewall with ping attempts and in addition there is some traffic trying to get through with a spoofed source address. What is going on and what can i do to strengthen the security on my network. Thanks in advance!
0
Comment
Question by:haddad05
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 34

Accepted Solution

by:
Dave_Dietz earned 250 total points
ID: 18784299
Sounds like someone is poking around your network using VNC.

You could try blocking that specific IP at the firewall, but that only stops that particular IP.
You could also try using a non-standard port for VNC - it won't stop a determined hacker from portscanning you to find a new open port but it would likely dissuade a less ardent attacker.

Not a whole lot you can do unless you can require authentication at the firewall.

Dave Dietz
0
 
LVL 5

Assisted Solution

by:dr_shivan
dr_shivan earned 250 total points
ID: 18834598
As an alternative, you can try to redirect your VNC to run on a different port other than the given default. This way, you can deter outsiders from trying their way in unless the correct port is given. Alternatively use the windows default remote desktop to do your tasks.
0

Featured Post

2017 Webroot Threat Report

MSPs: Get the facts you need to protect your clients.
The 2017 Webroot Threat Report provides a uniquely insightful global view into the analysis and discoveries made by the Webroot® Threat Intelligence Platform to provide insights on key trends and risks as seen by our users.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

SHARE your personal details only on a NEED to basis. Take CHARGE and SECURE your IDENTITY. How do I then PROTECT myself and stay in charge of my own Personal details (and) - MY own WAY...
In a recent article here at Experts Exchange (http://www.experts-exchange.com/articles/18880/PaperPort-14-in-Windows-10-A-First-Look.html), I discussed my nine-month sandbox testing of the Windows 10 Technical Preview, specifically with respect to r…
How to install and configure Citrix XenApp 6.5 - Part 1. In this video tutorial we have explained step by step installation of Citrix XenApp 6.5 Server on Windows Server 2008 R2 is explained in this video. We have explained the difference between…

734 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question