aw, crap, computer was running IIS ftp with anon enabled

tart666

Golden Member
May 18, 2002
1,289
0
0
damn stupid iis, enabling anonymous by default, and then warning you AGAINST turning it off...

the bigger problem was, Kerio was acting up, so I turned it off to test if was the problem. It was, so I switched to windows firewall. Which does not have "Trusted Zones". So ftp was open to everyone on the internet, with write-privileges access for anonymous.

Now, does anyone think I should format, or just a virusscan should suffice?
 

Crusty

Lifer
Sep 30, 2001
12,684
2
81
:Q

I would backup what you need and do a format, don't forget to get the logs and take the IP's and report them to their ISP.
 

spidey07

No Lifer
Aug 4, 2000
65,469
5
76
sorry, but I'd say format. as said, you have no idea what's running on that box and it would be easier to format than to clean.

Otherwise there are some articles on technet on how to remove files you can't seem to delete.
 

skyking

Lifer
Nov 21, 2001
22,217
5,076
146
a format, and some sort of firewall/router box would also be a good idea. No real reason to leave the entire port range of the internet there, hammering on your interface
 

tart666

Golden Member
May 18, 2002
1,289
0
0
Originally posted by: skyking
a format, and some sort of firewall/router box would also be a good idea. No real reason to leave the entire port range of the internet there, hammering on your interface

this is my office computer, we get real IP addresses, and the sysadmins are against NAT's on the users side. I guess I just have to make sure the computer stays patched, and that anonymous ftp is disabled
 

spidey07

No Lifer
Aug 4, 2000
65,469
5
76
Originally posted by: tart666
Originally posted by: skyking
a format, and some sort of firewall/router box would also be a good idea. No real reason to leave the entire port range of the internet there, hammering on your interface

this is my office computer, we get real IP addresses, and the sysadmins are against NAT's on the users side. I guess I just have to make sure the computer stays patched, and that anonymous ftp is disabled

your sysadmins need to be fired immediately. They allowed an internal host to be hacked?
 

tart666

Golden Member
May 18, 2002
1,289
0
0
Originally posted by: spidey07
your sysadmins need to be fired immediately. They allowed an internal host to be hacked?

I am at a college, so the network is pretty loose, it's all up to me I guess. I was running IIS so I could get some files off of my office computer when I am at home, I guess should be more careful with firewalls when IIS is on.

PS: anyone care to help me setup my MAPI through Sygate (Text) after all this? Please?

PPS: btw, this is after a reformat, clean SP2 install...
 

Zuke

Member
Oct 11, 1999
157
0
0
There's still no excuse for the situation. Lousy sysadins (if you can call 'em that).
 

Thor86

Diamond Member
May 3, 2001
7,886
7
81
Originally posted by: spidey07
Originally posted by: tart666
Originally posted by: skyking
a format, and some sort of firewall/router box would also be a good idea. No real reason to leave the entire port range of the internet there, hammering on your interface

this is my office computer, we get real IP addresses, and the sysadmins are against NAT's on the users side. I guess I just have to make sure the computer stays patched, and that anonymous ftp is disabled

your sysadmins need to be fired immediately. They allowed an internal host to be hacked?

I have to agree, this was sloppy and careless in their part.
 

VirtualLarry

No Lifer
Aug 25, 2001
56,450
10,119
126
I'm slightly amazed that an "office" network, isn't running some sort of perimeter firewall at the gateway, but instead depends on users to run a host-based firewall? Nothing against host-based protection, mind you, should a worm get past the front gates, but not having any "front gates" at all? Whoa.

PS. Don't forget to burn those movies to DVD before reformatting, you might need to save the "evidence", especially if the movies happen to be good ones.
 

DAPUNISHER

Super Moderator CPU Forum Mod and Elite Member
Super Moderator
Aug 22, 2001
28,826
21,611
146
Originally posted by: tart666the bigger problem was, Kerio was acting up, so I turned it off to test if was the problem. It was, so I switched to windows firewall. Which does not have "Trusted Zones". So ftp was open to everyone on the internet, with write-privileges access for anonymous.
The windows firewall in SP2 has an exceptions tab where you can uncheck the box next to your FTP software to prevent access. I run FlashFXP and it auto-added it to my exceptions control list and checked it as an exception by default so I just uncheck the box when not in use. I also have a router with NAT and another software firewall but I don't think the built-in firewall would do too bad a job on its own, not gonna find out though
 

bleuless

Senior member
Jul 25, 2001
437
0
76
Originally posted by: VirtualLarry
I'm slightly amazed that an "office" network, isn't running some sort of perimeter firewall at the gateway, but instead depends on users to run a host-based firewall? Nothing against host-based protection, mind you, should a worm get past the front gates, but not having any "front gates" at all? Whoa.

PS. Don't forget to burn those movies to DVD before reformatting, you might need to save the "evidence", especially if the movies happen to be good ones.

i wouldn't do it. might be kiddie porn or stuff that you don't want to see. who knows you could be traumatized for life.
 

ColdZero

Senior member
Jul 22, 2000
211
0
0
Thats actually a problem for office networks. In your agreement you have to either state it is not your responsibility to filter traffic or be ready to take the brunt of lawsuits from employees that may be traumitized.
 

ITJunkie

Platinum Member
Apr 17, 2003
2,512
0
76
www.techange.com
Originally posted by: spidey07
Originally posted by: tart666
Originally posted by: skyking
a format, and some sort of firewall/router box would also be a good idea. No real reason to leave the entire port range of the internet there, hammering on your interface

this is my office computer, we get real IP addresses, and the sysadmins are against NAT's on the users side. I guess I just have to make sure the computer stays patched, and that anonymous ftp is disabled

your sysadmins need to be fired immediately. They allowed an internal host to be hacked?

^Exactly^ Probably the only reason they are against NAT's are their lack of understanding them! Fire them now!!
 

tart666

Golden Member
May 18, 2002
1,289
0
0
Originally posted by: ITJunkie
Originally posted by: spidey07
Originally posted by: tart666
Originally posted by: skyking
a format, and some sort of firewall/router box would also be a good idea. No real reason to leave the entire port range of the internet there, hammering on your interface

this is my office computer, we get real IP addresses, and the sysadmins are against NAT's on the users side. I guess I just have to make sure the computer stays patched, and that anonymous ftp is disabled

your sysadmins need to be fired immediately. They allowed an internal host to be hacked?

^Exactly^ Probably the only reason they are against NAT's are their lack of understanding them! Fire them now!!

dude, in a university with 20,000 students, nobody's gonna listen to me... anyway, I guess i will try to get used to the xp firewall...
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |