Solved

Server 2000 Security question

Posted on 2007-03-21
2
213 Views
Last Modified: 2013-12-04
I manage a windows 2000 server and ive got a watchguard III 700 firewall. Ive noticed in the firebox system manager on the traffic monitor tab, it looks like someone is accessing our system when they should not be. The monitor says it allowed traffic from ip address 125.110.131.76 to different external addresses on my network. They are using port 5900 which i opened to enable remote access for VNC for certain users. There is also many denied attempts to get through the firewall with ping attempts and in addition there is some traffic trying to get through with a spoofed source address. What is going on and what can i do to strengthen the security on my network. Thanks in advance!
0
Comment
Question by:haddad05
2 Comments
 
LVL 34

Accepted Solution

by:
Dave_Dietz earned 250 total points
ID: 18784299
Sounds like someone is poking around your network using VNC.

You could try blocking that specific IP at the firewall, but that only stops that particular IP.
You could also try using a non-standard port for VNC - it won't stop a determined hacker from portscanning you to find a new open port but it would likely dissuade a less ardent attacker.

Not a whole lot you can do unless you can require authentication at the firewall.

Dave Dietz
0
 
LVL 5

Assisted Solution

by:dr_shivan
dr_shivan earned 250 total points
ID: 18834598
As an alternative, you can try to redirect your VNC to run on a different port other than the given default. This way, you can deter outsiders from trying their way in unless the correct port is given. Alternatively use the windows default remote desktop to do your tasks.
0

Featured Post

The Eight Noble Truths of Backup and Recovery

How can IT departments tackle the challenges of a Big Data world? This white paper provides a roadmap to success and helps companies ensure that all their data is safe and secure, no matter if it resides on-premise with physical or virtual machines or in the cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Many people tend to confuse the function of a virus with the one of adware, this misunderstanding of the basic of what each software is and how it operates causes users and organizations to take the wrong security measures that would protect them ag…
Container Orchestration platforms empower organizations to scale their apps at an exceptional rate. This is the reason numerous innovation-driven companies are moving apps to an appropriated datacenter wide platform that empowers them to scale at a …
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
How to install and configure Citrix XenApp 6.5 - Part 1. In this video tutorial we have explained step by step installation of Citrix XenApp 6.5 Server on Windows Server 2008 R2 is explained in this video. We have explained the difference between…

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question