New domains / workgroups aopearing in our MS Network

New domains / workgroups aopearing in our MS Network

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
New domains / workgroups aopearing in our MS Network Scott Berger 09-13-2006
Posted by =?Utf-8?B?U2NvdHQgQmVyZ2Vy?= on September 13, 2006, 4:01 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
We had something odd happen in the last day or two. Some unusual
domain/workgroup names appeared in our Microsoft Network family in the
network places area. They had some interesting names that indicated a german
origin, like MSHeimNetz, and a german looking surname. My question is what
happens that causes items in that folder? We tried clicking on them, but they
dont respond. They also just disappeared. I feel like we've been hacked.

Does any of this scenario sound familiar?


Posted by Joseph Bittman MVP MCSD on September 13, 2006, 5:26 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Sept. 13, 2006

Definitely sounds like a hack to me... if you are using a wifi network,
check and make sure unauthorized computers haven't connected to your
router... and perhaps change your router password.

If you are using a wired network, then check and make sure nobody's
connected another computer to it.

Lastly, to see if this is a hack... I'd take some of those names and input
them into google or msn search... "MSHeimNetz" pulls up some very
interesting search results, but unfortunately I don't speak German.

A friend pointed me to a language tranlsation web site...
http://babelfish.altavista.com - try sticking some search results into there
from those weird names.

Good luck!

--

Joseph Bittman
Microsoft Certified Solution Developer
Microsoft Most Valuable Professional -- DPM

Blog/Web Site: http://CactiDevelopers.ResDev.Net/
> We had something odd happen in the last day or two. Some unusual
> domain/workgroup names appeared in our Microsoft Network family in the
> network places area. They had some interesting names that indicated a
> german
> origin, like MSHeimNetz, and a german looking surname. My question is what
> happens that causes items in that folder? We tried clicking on them, but
> they
> dont respond. They also just disappeared. I feel like we've been hacked.
>
> Does any of this scenario sound familiar?
>


Posted by Steven L Umbach on September 13, 2006, 8:28 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
One possibility is that someone put a computer like a laptop on your network
with those workgroup names or VPN into your network with the same. Entries
in My Network Places require port 137 access and use mostly broadcasts to
maintain the browse list. You might want to check your wins database, DHCP
leases, and DNS records to see if you find any unusual computer names that
may provide a clue. Though what happened is curious it does not necessarily
mean that your network has been compromised.

Steve


> We had something odd happen in the last day or two. Some unusual
> domain/workgroup names appeared in our Microsoft Network family in the
> network places area. They had some interesting names that indicated a
> german
> origin, like MSHeimNetz, and a german looking surname. My question is what
> happens that causes items in that folder? We tried clicking on them, but
> they
> dont respond. They also just disappeared. I feel like we've been hacked.
>
> Does any of this scenario sound familiar?
>



Similar ThreadsPosted
lookupaccountname and workgroups December 11, 2007, 4:43 am
Authentication across untrusted domains March 29, 2006, 1:16 am
Setting up 2 domains with one way trust to dmz November 14, 2006, 5:58 pm
Domain Admin can't log into child domains February 15, 2006, 7:19 pm
Assigning Security through W2k3 to W2k Trusted Domains March 14, 2006, 1:52 pm
Corporate Network Connection w/ additional Untrusted Network via E February 24, 2006, 8:41 pm
domaine vergabe free de domains domain de eu domain name registrieren de be domain July 28, 2008, 4:14 pm
NETWORK and NETWORK SERVICE accounts April 21, 2006, 10:05 am
RE: Network August 13, 2008, 6:12 pm
Anyone can browse my network June 29, 2005, 4:21 pm

The site map in XML format XML site map

Contact Us | Privacy Policy