Link to home
Start Free TrialLog in
Avatar of gregmiller4it
gregmiller4itFlag for Australia

asked on

We are being targeted by a hacker

Our DC is SBS2003 and we also have a Server 2003 as a Terminal Server. We are using a Cisco Small Business Pro SRP527W modem/router.
For weeks we have been the target of someone trying to login remotely. I can get up to tens of thousands failed login attempts on any one night. These show up in the daily report that I recieve each morning. Mostly it shows a login name that failed as bad username or password. It was trying the Administrator account at first but I changed the name of that account to stop that. Our user accounts are based on each user's real name, so it could be only a matter of time until they latch onto a real user account. Then they can use brute force to get in.
One thing that I have noticed is that the failed attempts seem to use random ports. I wondered if the way forward might be to block all ports in our modem/router, but I can't work out how to do that.
Any suggestions? My fear is that it could just be a matter of time before they get in.

Cheers,
Greg
SOLUTION
Avatar of Syed Muhammad Usman
Syed Muhammad Usman
Flag of Bahrain image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of gregmiller4it

ASKER

Thanks for all the responses. I have done most of what has been suggested. we do need RDP and have changed the port number. We do have a reasonably complex password requirement enforced.  I have enabled all the filters in our Cisco modem/firewall that i can. Unfortunately, our firewall won't allow me to block specific IP addresses or ports.<br />I may have to look at another firewall with more features.<br />Cheers,<br />Greg