| Hernán Castelo 2004-06-28, 7:33 pm |
| i deploy
the "best practices"
according to MS
but it was not enough
what should i do now?
how can i secure the web server now ?
--
atte,
Hernán
"Hernán Castelo" <hcastelo@cedi.frba.utn.edu.ar> escribió en el mensaje news:%23GBjOhRXEHA.2636@TK2MSFTNGP10.phx.gbl...
hi
someone was hacked my site
i have 2 servers :
web--> IIS 5 / w2k adv Srv IIS lockdown
sql--> SQL2k / w2k adv Srv
i found the web srv doing "beeps"
soon i found it serves html pages
but don't serves asp with an error like
"Error in the server application"
sql srv lost sa password
and don't recognize the local admin
then i can't access to sql applications
except of that,
servers appears to work normal
the web srv log is saying
that attacked the iwam_
and many "login misses" under DCOMSCM
and then, "login hits"
i go now to restore
my backup and images
but
what can i do to prevent the next attack ?
how can i protect better the site ?
thanks
--
atte,
Hernán
|