Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Folders that can't be opened, deleted, no Admin access

Status
Not open for further replies.

jmchang

IS-IT--Management
Oct 21, 2003
2
US
I have a problem with a four folders that can't be opened or deleted. I believe someone "trusted" set an illegal ftp site up and denied access to the folder for everyone, including the administrator. The folders have no security tabs. I can't change attributes. I have disabled the IIS service on the server for now. The server is a Windows 2000 Serer SP4.

Any information would be great, as this is a server for public school and the faster it's up the better.

Thanks
 
Cannot really help you with the problem but We had a similar thing happen, and it was not a "Trusted" person that set up the ftp site. The system was hacked from outside and we had to rebuild the system. You probably have been HACKED. Therefore I would not trust anything on the system. They may have replaced explorer or ie etc etc.. ie you dont control the system anymore.

After you rebuild I would make sure that you have the latest hotfixes and Service packs and get a firewall on the box as well.
 
See the problems is I have the server up to date, and I'm behind a firewall. Do you know how they did this so I can prevent it from happening again after I rebuild my server?

thanks
 
Sounds like someone is using your server for storage or distribution, quite likely things you don't want there...

Firewalls are only as good as you set them. I'd expect that you've closed all ports on the router(s) except the relatively few needed for expected traffic. But last I heard the saying "Anything can be hacked if the hacker is determined" is even more true today, but you can (and probably did) make it hard to be hacked. The gloves have come off and the bad guys are not lurking in the background anymore!

Besides being behind a firewall, best practices says:

Turn off and/or remove unneeded services

Protect critcal but powers system tools and commands such as command.com, cmd.exe, edit.com and others (In NT4 admins were told to either "hide" them by moving them to a separate utility directory you can specify or rename them, but I think in Win2000 you can configure administrator level permissions, though a hacker may have ways around that...)


Don't forget to have a virus scanner running on the mail server checking all emails coming in, as someone may have snuck the loader for the hack in an attachment

I don't want to think about internet browsers hitting a hacked site...

Don't forget to have all the network computers scanned with up-to-date AV software, maybe SpyBot too.
 
Have you thought about or tried any password hacker software? It may be worth looking into.
 
There are other forums more focused on the hacker/virus issues so see if they can help more...
General Security Discussion Forum: forum83
General Virus Discussion Forum: forum760
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top