best practices
Web Server forum
Back To The Forum Home!Search!Private Messaging System

Web Server Talk Web Server Talk > Web Servers reviews > IIS server support > IIS Server Security > best practices




  Last Thread   Next Thread Next
  Show Printable Version Email this Page Subscribe to this Thread      Post New Thread    Post A Reply      

    best practices  
Hernán Castelo


View Ip Address Report This Message To A Moderator Edit/Delete Message


 
06-29-04 12:33 AM

i deploy
the "best practices"
according to MS
but it was not enough

what should i do now?

how can i secure the web server now ?



-- 
atte,
Hernán 


"Hernán Castelo" <hcastelo@cedi.frba.utn.edu.ar> escribió en el mensaje news
:%23GBjOhRXEHA.2636@TK2MSFTNGP10.phx.gbl...
hi
someone was hacked my site
i have 2 servers :
web--> IIS 5 / w2k adv Srv IIS lockdown
sql--> SQL2k / w2k adv Srv

i found the web srv doing "beeps"
soon i found it serves html pages
but don't serves asp with an error like
"Error in the server application"

sql srv lost sa password
and don't recognize the local admin
then i can't access to sql applications

except of that,
servers appears to work normal

the web srv log is saying
that attacked the iwam_
and many "login misses" under DCOMSCM
and then, "login hits"

i go now to restore
my backup and images
but
what can i do to prevent the next attack ?
how can i protect better the site ?

thanks


-- 
atte,
Hernán






[ Post a follow-up to this message ]



    Sponsored Links  




 





   All times are GMT. The time now is 09:04 AM.      Post New Thread    Post A Reply      
  Last Thread   Next Thread Next


Most Popular forums 

Forum Jump:
Rate This Thread:

Forum Rules:
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is OFF
vB code is ON
Smilies are ON
[IMG] code is OFF
 
Medical and Health forum | Computer Games Reviews | Graphics design forum

Back To The Top
Home | Usercp | Faq | Register